Aller au contenu

Fiche vulnérabilité

CVE-2026-100596 : vulnérabilité élevée (CVSS 8.8)

Description

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 sept. 2026
Dernière mise à jour
26 sept. 2026

Références

Rechercher une autre vulnérabilité dans la base CVE