Impact
OpenClaw's sandbox exec-server was discovered to allow lower-trust callers to send HTTP requests that bypass the configured network policy, granting access to internal destinations that should have been blocked. The flaw corresponds to a CWE-918 weakness, undermining the integrity of network segmentation by letting attackers reach services protected by OpenClaw's policy gateways. The direct consequence is the potential compromise of confidential internal data and operations that rely on the network rules to isolate segments.
Affected Systems
The issue affects all OpenClaw releases older than version 2026.6.6 that include the exec-server component. Users running any pre-2026.6.6 build are vulnerable; no specific sub-versions are singled out beyond the general cutoff.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity because the vulnerability does not grant elevated privileges or direct code execution, but it does provide a network policy bypass. An EPSS score of less than 1% shows that the likelihood of exploitation in the wild is low, and the flaw is not currently listed in the CISA KEV catalog. Attackers need only be able to send crafted HTTP requests to the exec-server endpoint from any host that can reach the OpenClaw service.
OpenCVE Enrichment