Impact
OpenClaw versions earlier than 2026.8.1 contain an authorization scope widening vulnerability in the file‑transfer module’s allow‑always approvals. The flaw lets an attacker re‑use standing grant rights to submit file‑transfer requests for paths that were not originally approved. By exploiting glob metacharacter handling and node display name reuse, the attacker can reach sibling or unrelated nodes beyond the operator’s intended scope, effectively bypassing authorization checks.
Affected Systems
The vulnerability affects all OpenClaw installations using releases older than 2026.8.1. This includes every instance of the OpenClaw product that has not yet applied the 2026.8.1 update or later.
Risk and Exploitability
The CVSS score of 7.4 signals a high‑severity compromise risk. Though no EPSS value is available, the lack of a KEV listing does not diminish the potential for exploitation; attackers with access to the file‑transfer interface could elevate privileges and access unauthorized file paths. Because the flaw relies on configuration mistakes and glob interpretation, the attack can be carried out remotely by users who have already been granted file‑transfer permissions, but the window of exposure widens when allow‑always approvals are enabled.
OpenCVE Enrichment