High priorityDisclosed

Advisory · CVE-2026-101882

OpenClaw Windows Node lets callers self-grant blanket command execution with wildcard rules

system.execApprovals.set accepts broad wildcard allow rules such as *.* that match nearly every command, letting a caller weaken the exec-approval policy into arbitrary code execution.

Vendor
openclaw
Product
OpenClaw Windows Node
Identifier / CWE
CVE-2026-101882
CWE-863, CWE-184
Action timing
Immediate
ELI5

Explain it like I’m five

The bouncer checks the guest list before letting commands in, but an attacker can add their own entry to the guest list, and the bouncer accepts a name like 'anyone with a dot' as a valid guest.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Caller reaches policy API

    A gateway or agent with access to system.execApprovals.set faces only the tray permission toggle and a rule validator, with no admin authorization or user prompt on the call itself.

  2. 02Wildcard rule passes validation

    ValidateExecApprovalRules rejects only enumerated broad shapes (*, **, ?*), so a pattern with one non-wildcard character such as *.* or *e* passes.

  3. 03Matcher is near-blanket

    The policy compiles each rule to an anchored regex with * mapped to .* over the whole command line, so *.* matches essentially every real Windows invocation.

  4. 04Gate neutralized

    After the rule is accepted, system.run executes arbitrary commands with no prompt, turning a read-only policy into full host control.

What happened

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set. The call lets a caller rewrite the exec-approval policy, and ValidateExecApprovalRules is the backstop meant to stop a caller from weakening the policy into arbitrary execution. The check blocks the all-wildcard shapes (*, **, ?*), shell-blanket shapes (powershell *, cmd *), an allow-by-default action, absolute paths, and a denylist of dangerous fragments. But the broad-rule check is a denylist of enumerated shapes, while the policy matcher compiles every rule to an anchored regex with * mapped to .* over the whole command line. Any allow pattern whose executable is wildcarded, such as *.*, *e*, *.exe, or c*, passes validation yet matches nearly every command. A single such rule turns system.run into arbitrary command execution with no prompt, neutralizing the entire exec-approval gate.

The vulnerability is rated high at CVSS 8.8 and is fixed in OpenClaw Windows Node 2026.7.1, which requires the executable an allow rule names to be a concrete literal.

What to do

  1. Inventory Windows nodes running OpenClaw Windows Node before 2026.7.1.
  2. Upgrade to v2026.7.1 or later.
  3. Audit the exec-approval policy on every node for broad wildcard allow rules that may have been injected.
  4. Review command execution history for activity that should have prompted but did not.
  5. Rotate any credentials or tokens that were reachable from a node with an exposed policy endpoint.

Management note

This is the companion failure to the shell-parser bypass in the same policy subsystem: the control that constrains an AI agent’s actions could be rewritten by the agent itself. Together they show why agent permission boundaries need adversarial testing, not just configuration. Anyone running OpenClaw Windows Node with the system-tools toggle enabled should treat pre-2026.7.1 policy state as untrusted.