CVE-2026-32058: OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32058?
CVE-2026-32058 is rated as a medium severity vulnerability due to its potential impact on the execution integrity of approved requests.
How do I fix CVE-2026-32058?
To fix CVE-2026-32058, update OpenClaw to version 2026.2.26 or later.
What types of systems are affected by CVE-2026-32058?
CVE-2026-32058 affects OpenClaw versions prior to 2026.2.26 that utilize the system.run execution flow with host=node.
What does CVE-2026-32058 allow an attacker to do?
CVE-2026-32058 allows an attacker to potentially reuse previously approved requests by modifying their environment variables, which could bypass security measures.
Is there a workaround for CVE-2026-32058?
There are no official workarounds for CVE-2026-32058; upgrading to the patched version is the recommended solution.