rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.7 · EPSS 0.00246

CVE-2026-100596

OpenClaw versions prior to 2026.7.1 allow non‑owner users to execute /mcp set and /mcp unset commands, enabling persistence of malicious MCP

Overview

OpenClaw versions prior to 2026.7.1 allow non‑owner users to execute /mcp set and /mcp unset commands, enabling persistence of malicious MCP commands that run with OpenClaw process privileges. This flaw can lead to unauthorized changes to system configuration, exposing the host to confidentiality, integrity, and availability risks. The vulnerability is critical and can be exploited by any authenticated user with access to the OpenClaw interface.

Description

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

Impact

Defenders and system administrators are directly impacted, as the flaw permits unauthorized configuration changes that can compromise host confidentiality, integrity, and availability. Attackers can persist malicious commands that execute with elevated privileges, potentially leading to full system compromise. Security teams must monitor for anomalous MCP activity and enforce strict access controls.

Remediation

Apply the 2026.7.1 patch or later to fix the authorization flaw. Until patching, restrict /mcp set and /mcp unset commands to owner users only, disable MCP configuration changes for non‑owners, and enforce least privilege on OpenClaw processes. Enable file integrity monitoring on MCP configuration files and audit logs for unauthorized changes.

Risk context

The CVE is rated critical with a CVSS v3 score of 8.8 and a low EPSS of 0.00246, indicating a high severity but low likelihood of exploitation in the wild. Defenders should treat this as a high‑priority issue and apply mitigations promptly.

Affected products

  • OpenClaw 2026.6
  • OpenClaw 2026.5
  • OpenClaw 2026.4
  • OpenClaw 2026.3
  • OpenClaw 2026.2
  • OpenClaw 2026.1
  • OpenClaw 2026.0
  • OpenClaw 2025

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
8.7
EPSS
0.00246

authorization privilege_escalation config_manipulation openclaw critical mcp process_privileges

← All CVEs