CVE-2026-100596: OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.7.1
Event History
Frequently Asked Questions
Which deployments are affected?
OpenClaw versions earlier than 2026.7.1 are affected. Deployments where non-owner users can issue MCP configuration commands should be prioritized.
What level of access does an attacker need?
The attacker needs low-level privileges as a non-owner user. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.
What can a successful attacker do?
An attacker can persist arbitrary stdio MCP commands that run with the OpenClaw process privileges when configuration is loaded. This can compromise host confidentiality, integrity, and availability.