Description
OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.
Published: 2026-07-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.6.9 allow a lower‑trust caller to invoke isolated cron jobs in a way that bypasses denied execution tools, effectively giving the caller permission to run commands or persist actions beyond their intended authorization. The vulnerability stems from misconfigured input paths that the cron feature accepts, leading to a privilege escalation scenario where an attacker can gain broader access to the system. This flaw can compromise the integrity of the application and the confidentiality of data controlled by higher‑privileged users.

Affected Systems

The affected product is OpenClaw from the OpenClaw vendor. The vulnerability exists in OpenClaw releases 2026.6.1 through 2026.6.8. The software runs on a Node.js runtime environment. No other products or versions are listed as impacted.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity vulnerability when exploited. The EPSS score of less than 1% suggests that public exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw arises from privileges granted within isolated cron jobs, the attack vector is likely internal; a user that can trigger low‑trust cron jobs may exploit the misconfiguration to gain elevated rights. In the absence of a publicly documented exploit, the risk remains primarily theoretical but the potential for intense damage warrants immediate attention.

Generated by OpenCVE AI on July 31, 2026 at 00:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OpenClaw release 2026.6.9 or newer to address the cron privilege escalation flaw.
  • If patching cannot be applied immediately, temporarily disable the cron jobs that accept external or untrusted input paths to prevent escalation attempts.
  • Audit and tighten input validation for all cron job configurations, ensuring that only authorized and whitelisted paths are processed to mitigate future misconfiguration risks.

Generated by OpenCVE AI on July 31, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.
Title OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-18T03:55:30.253Z

Reserved: 2026-07-13T16:38:58.353Z

Link: CVE-2026-62202

cve-icon Vulnrichment

Updated: 2026-07-17T14:00:35.300Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses