CVE-2026-34426: OpenClaw - Approval Bypass via Environment Variable Normalization
Published Apr 2, 2026
·Updated
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment variables into execution without approval system validation. Attackers can exploit differing normalization logic to discard non-portable keys during approval processing while accepting them at execution time, bypassing operator review and potentially influencing runtime behavior including execution of attacker-controlled binaries.
Affected Software
1 affected component
OpenClaw Openclaw Node.js<2026.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Patch b57b680
Event History
Apr 2, 2026
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:21 PM
RemedyDescriptionSeverityWeaknessAffected Software