EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all intelligence correlata
Vulnerabilità

CVE-2026-100584

Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.

Condivisione
PUBLIC-OSINT
Confidenza
100
Fonte
The CVE Program
Aggiornata
26/09/2026 08:15

Descrizione

OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust content can place an executable with an approved basename into an agent-writable workspace and steer an approved PowerShell command that uses a bare executable name, OpenClaw may run the workspace file instead of the allowlisted path, executing arbitrary code with the privileges of the Gateway or node-host user. The issue does not require replacement of the approved executable itself. Version 2026.7.1 contains a fix; as a workaround, avoid bare executable names in approved PowerShell commands and keep executable files out of agent-writable workspaces.

Identificativo STIXvulnerability--5467eded-33f3-53db-9d6b-76ff5e2a7c19
Prima osservazione-
Ultima osservazione-
Relazioni censite6

Alias e classificazioni

CWE-426Untrusted Search Path

Dettagli tecnici minimizzati

Nessun dato grezzo
cisa kev
False
cvss score
6.7
cvss vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
cvss severity
MEDIUM
Correlazione EudorIA

Catalogo Intel

La vulnerabilit&agrave; &egrave; presente anche nel catalogo editoriale EudorIA.

Apri analisi EudorIA

La presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.