CVE-2026-32023 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch wrappers can…
Medium CVSS: 6.0

CVE-2026-32023

OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch wrappers can suppress shell-wrapper detection. Attackers can exploit this by chaining multiple dispatch wrappers like /usr/bin/env to execute /bin/sh -c commands without triggering the expected approval prompt in allowlist plus ask=on-miss configurations.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-863
Yayın Tarihi
2026-03-19 22:16:36
Güncelleme
2026-03-25 15:16:45
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar