LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-27545

openclaw · openclaw

Published
CVSS6.1
Severitymedium
WeaknessCWE-367
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Description

OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current working directory after approval. An attacker can modify mutable parent symlink path components between approval and execution time to redirect command execution to a different location while preserving the visible working directory string.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-27545

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-27545.