---
id: CVE-2026-101880
title: >-
  OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization
  vulnerability in the system.run exec-approval policy where
  ExecShellWrapperParser fails to split commands on pipe operators or extract
  command substitutions
summary: >-
  OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization
  vulnerability in the system.run exec-approval policy where
  ExecShellWrapperParser fails to split commands on pipe operators or extract
  command substitutions. Conne…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: OpenClaw
product: OpenClaw Windows Node
affected:
  - windows_node < 2026.7.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:18.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101880'
references:
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecShellWrapperParser.cs#L253
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/commit/2077aa3e7159101bddcee2f4efcb9d604a81619e
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-vg38-vjq2-vgvh
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-authorization-bypass
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-30T19:33:47.048317Z'
ingestedAt: '2026-09-30T20:23:19.511Z'
---

## Overview

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
