HarborGuard / CVE
Back to search
HIGHCVE-2026-41390Published Modified CNA VulnCheck

CVE-2026-41390: OpenClaw < 2026.3.28 - Exec Allowlist Bypass via Unregistered /usr/bin/script Wrapper

OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. Attackers can obtain user approval for one wrapped command to persist trust for wrapper binaries that execute different underlying programs.

Metrics

CVSS v4.0
7.0
Severity
HIGH
Fixed in
2026.3.28
Affected Products
1

Fix available

2026.3.28
Affected packages
  • OpenClaw / OpenClaw
    < 2026.3.28 (from 0)
    Fixed in 2026.3.28
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N