Advisory · CVE-2026-101882
OpenClaw Windows Node lets callers self-grant blanket command execution with wildcard rules
system.execApprovals.set accepts broad wildcard allow rules such as *.* that match nearly every command, letting a caller weaken the exec-approval policy into arbitrary code execution.
- Vendor
- openclaw
- Product
- OpenClaw Windows Node
- Identifier / CWE
- CVE-2026-101882
CWE-863, CWE-184 - Action timing
- Immediate
Explain it like I’m five
The bouncer checks the guest list before letting commands in, but an attacker can add their own entry to the guest list, and the bouncer accepts a name like 'anyone with a dot' as a valid guest.
- 01Caller reaches policy API
A gateway or agent with access to system.execApprovals.set faces only the tray permission toggle and a rule validator, with no admin authorization or user prompt on the call itself.
- 02Wildcard rule passes validation
ValidateExecApprovalRules rejects only enumerated broad shapes (*, **, ?*), so a pattern with one non-wildcard character such as *.* or *e* passes.
- 03Matcher is near-blanket
The policy compiles each rule to an anchored regex with * mapped to .* over the whole command line, so *.* matches essentially every real Windows invocation.
- 04Gate neutralized
After the rule is accepted, system.run executes arbitrary commands with no prompt, turning a read-only policy into full host control.
What happened
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set. The call lets a caller rewrite the exec-approval policy, and ValidateExecApprovalRules is the backstop meant to stop a caller from weakening the policy into arbitrary execution. The check blocks the all-wildcard shapes (*, **, ?*), shell-blanket shapes (powershell *, cmd *), an allow-by-default action, absolute paths, and a denylist of dangerous fragments. But the broad-rule check is a denylist of enumerated shapes, while the policy matcher compiles every rule to an anchored regex with * mapped to .* over the whole command line. Any allow pattern whose executable is wildcarded, such as *.*, *e*, *.exe, or c*, passes validation yet matches nearly every command. A single such rule turns system.run into arbitrary command execution with no prompt, neutralizing the entire exec-approval gate.
The vulnerability is rated high at CVSS 8.8 and is fixed in OpenClaw Windows Node 2026.7.1, which requires the executable an allow rule names to be a concrete literal.
What to do
- Inventory Windows nodes running OpenClaw Windows Node before 2026.7.1.
- Upgrade to v2026.7.1 or later.
- Audit the exec-approval policy on every node for broad wildcard allow rules that may have been injected.
- Review command execution history for activity that should have prompted but did not.
- Rotate any credentials or tokens that were reachable from a node with an exposed policy endpoint.
Management note
This is the companion failure to the shell-parser bypass in the same policy subsystem: the control that constrains an AI agent’s actions could be rewritten by the agent itself. Together they show why agent permission boundaries need adversarial testing, not just configuration. Anyone running OpenClaw Windows Node with the system-tools toggle enabled should treat pre-2026.7.1 policy state as untrusted.