Junglewise Threat Intelligence

CVE-2026-27486: OpenClaw unvalidated PID kill via SIGKILL in process cleanup

CVE-2026-27486 · Severity: medium · CVSS 4 · Published 2026-02-18

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a CLI tool that manages process cleanup during execution. A vulnerability in its process termination logic could kill unrelated processes on shared hosts if they matched the tool's command-line patterns, causing unexpected service disruptions or resource exhaustion even if the attacker does not directly control the OpenClaw process.

Technical details

The vulnerability is a failure to verify resource ownership (CWE-283) in OpenClaw's CLI runner cleanup helpers. The affected code uses system-wide process enumeration and pattern matching to terminate processes via SIGKILL without validating that those processes are owned by the current OpenClaw instance. On multi-tenant or shared hosts, an attacker with local access and permission to run OpenClaw can cause the tool to terminate arbitrary unrelated processes that match the pattern, leading to denial of service. The fix filters cleanup operations to direct child processes only (ppid == process.pid) and introduces SIGTERM before SIGKILL for graceful shutdown attempts.

Affected products

  • OpenClaw OpenClaw < 2026.2.14

Timeline

  • 2026-02-18: disclosed: Advisory published
  • 2026-02-14: patched: Fix version 2026.2.14 (planned release)

References

Related threats