Back

HIGH

OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration

Published Sep 26, 2026

Description

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Sep 26, 2026
Updated Oct 5, 2026
Reserved Sep 26, 2026

CISA Vulnrichment

Updated Oct 5, 2026

NVD

Status Deferred
Modified Oct 5, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Sep 26, 2026
Updated Oct 5, 2026

GitHub

No data