Boletines de Vulnerabilidades

CVE-2026-100560

   
Software afectado MACOS
 
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-100560