rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.7 · EPSS 0.00246

CVE-2026-100586

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings.…

Description

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
8.7
EPSS
0.00246

← All CVEs