Technology · Openclaw
Openclaw vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 973 vulnerabilities in Openclaw: 56 in the last 7 days and 127 in the last 90 days, 14 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100599, was published on 26 September 2026.
- Last 7 days
- 56
- Last 90 days
- 127
- Critical, all time
- 14
- Exploited in the wild
- 0
Latest Openclaw vulnerabilities
- CVE-2026-100599: OpenClaw exec approval bypass in Google Meet node commandshighCVSS 8.8
- CVE-2026-100598: OpenClaw Signal approval reaction binding logic errorhighCVSS 7.1
- CVE-2026-100597: OpenClaw time-of-check time-of-use race condition in filesystem operationshighCVSS 7.8
- CVE-2026-100596: OpenClaw authorization bypass in MCP configurationhighCVSS 8.8
- CVE-2026-100595: OpenClaw authorization bypass in diagnostics exportmediumCVSS 6.5
- CVE-2026-100594: OpenClaw authorization bypass in /export-trajectory endpointmediumCVSS 6.5
- CVE-2026-100593: OpenClaw authorization bypass in activation policymediumCVSS 5.4
- CVE-2026-100592: OpenClaw authorization bypass in memory dreaming commandsmediumCVSS 6.3
- CVE-2026-100591: OpenClaw missing owner authorization check on Active Memory global togglesmediumCVSS 6.3
- CVE-2026-100590: OpenClaw authorization bypass in /voice set commandmediumCVSS 4.3
- CVE-2026-100589: OpenClaw sandbox bypass in browser toolhighCVSS 8.3
- CVE-2026-100588: OpenClaw authorization bypass in node.invoke browser controlhighCVSS 8.3
- CVE-2026-100587: OpenClaw missing authorization in Codex computer-use installhighCVSS 8.8
- CVE-2026-100585: OpenClaw authorization bypass in Claude Code permission promptshighCVSS 8
- CVE-2026-100584: OpenClaw arbitrary code execution via PATH search allowlist bypassmediumCVSS 6.7
- CVE-2026-100580: OpenClaw case sensitivity bypass in cron toolhighCVSS 8.8
- CVE-2026-100579: OpenClaw authorization bypass via spoofed requester identityhighCVSS 7.6
- CVE-2026-100578: OpenClaw authorization bypass in chat.send endpointhighCVSS 7.6
- CVE-2026-100577: OpenClaw server-side request forgery in video asset handlingmediumCVSS 6.3
- CVE-2026-100576: OpenClaw server-side request forgery in browser wait predicatesmediumCVSS 5.4
- CVE-2026-100574: OpenClaw server-side request forgery in DNS validationmediumCVSS 5.9
- CVE-2026-100572: OpenClaw rate-limit bypass in Synology Chat webhooksmediumCVSS 5.3
- CVE-2026-100571: OpenClaw SMS webhook rate limit bypassmediumCVSS 5.3
- CVE-2026-100570: OpenClaw argument injection in Gmail setuphighCVSS 7.8
- CVE-2026-100569: OpenClaw workspace environment-variable filter credential exposuremediumCVSS 5.5
Most severe Openclaw vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33579: OpenClaw privilege escalation in device pairing approvalcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-32917: OpenClaw remote command injection in iMessage attachment stagingcriticalCVSS 9.8EPSS 3.2%
- CVE-2026-28474: OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display…criticalCVSS 9.8EPSS 0.9%
- CVE-2026-53838: OpenClaw state mutation in node pairing reconnectioncriticalCVSS 9.8EPSS 0.4%
- OpenClaw node pairing state mutation on reconnectioncriticalCVSS 9.8
- OpenClaw authentication bypass in Feishu webhook validationcriticalCVSS 9.8
- CVE-2026-44112: OpenClaw TOCTOU race condition in OpenShell sandbox filesystem writescriticalCVSS 9.6EPSS 0.4%
- CVE-2026-41294: OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeovercriticalCVSS 9.6EPSS 0.2%
- CVE-2026-32916: OpenClaw authorization bypass in plugin subagent routescriticalCVSS 9.4EPSS 0.6%
- OpenClaw QQBot authorization bypass in admin commandscriticalCVSS 9.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 29 | 1 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 39 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 55 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/openclaw.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Openclaw vulnerabilities", https://junglewise.ai/threats/technologies/openclaw, 26 September 2026.