Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-26

HighVendor post

OpenClaw Flaws Let Steered Agents Cross Owner, Sandbox, and Execution-Approval Boundaries

Analysis of four OpenClaw flaws that exposed owner-only tools, persistent cron execution, paired-node browser control, and Google Meet node commands to steered agents.

OpenClawGovernance bypassAgent-reachable authorization, sandbox, and execution-approval bypassesOpenClaw versions before 2026.7.1, including identity-bearing Gateway deployments, the model-facing cron tool, paired browser nodes, and Google Meet node commands

What happened

In the disclosed scenarios, steered agents could invoke owner-only gateway or cron tools, persist attacker-selected host commands, manipulate a paired browser profile, or execute processes on a paired Google Meet node without the intended approval path.

Why it matters

Potential persistent configuration changes, host file and credential access, manipulation of authenticated browser state, arbitrary process execution on paired nodes, and service availability impact.

Missing authorization check

A uniform execution-time decision binding the authenticated caller, agent, normalized tool and arguments, target node, resource, and required approval before every privileged operation.

Would PP block it?

A receipt checked at each independently enforced host, browser, scheduler, or node boundary would bind the normalized action and target. A steered agent's access to a tool name would not by itself authorize the operation. Coverage depends on placing the gate outside the compromised OpenClaw path.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-09-26

    CVE-2026-100578, CVE-2026-100580, CVE-2026-100589, and CVE-2026-100599 are published with coordinated OpenClaw advisories.

  2. 2026-09-26

    OpenClaw 2026.7.1 is identified as the fixed release for all four issues.

Technical breakdown

  • chat.send could start a non-owner turn with owner-only gateway and cron tools in its inventory in identity-bearing deployments.
  • The model-facing cron guard checked a payload kind before normalization, so mixed case could later become a persistent command job.
  • Sandboxed sessions could select paired-node browser actions even when allowHostControl=false was configured.
  • The googlemeet.chrome command accepted caller-supplied audio command arrays and executed them on a paired node without the normal system.run approval path.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Host process, paired-node browser, cron scheduling, and plugin command boundaries outside the model-facing tool router
Still needs
Permission Protocol does not repair OpenClaw's internal tool inventory, case normalization, sandbox routing, or Google Meet plugin command path. Ungated operations inside the same compromised runtime remain exposed.
Receipt required for
Executing the exact normalized gateway, cron, browser-node, or paired-node command for a named caller, agent, target, and expiry

External Runtime and Tool-Call Gates can require payload-bound authority before host commands, browser actions, scheduling changes, or paired-node execution leave the OpenClaw runtime.

Start small

Put the relevant gate at this action boundary.

This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop