CVE-2026-100568: OpenClaw before 2026.8.1 Unauthorized Command Job Access
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Who can exploit this issue?
A model-visible agent caller with low-privileged access can exploit it. No user interaction is required, and exploitation can be performed remotely according to the supplied vector.
What can an attacker do through the exposed command jobs?
An attacker can read ownerless operator command cron jobs, including stored environment variables that may contain secrets. They can also force-run disabled or unscheduled jobs, causing operator-authored commands to execute.
Which deployments are affected?
OpenClaw versions before 2026.8.1 are affected. The issue specifically concerns deployments with ownerless operator command cron jobs that are visible to agent callers.