CVE-2026-22169
Last modified
CVE-2026-22169 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.2.22 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-22169?
How severe is CVE-2026-22169?
How do I fix CVE-2026-22169?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22163Requires malware code to misuse the DDK kernel module IOCTL …7.8
- CVE-2026-22164Software installed and run as a non-privileged user may cond…7.5
- CVE-2026-22165A web page that contains unusual WebGPU content loaded into …8.1
- CVE-2026-22166A web page that contains unusual WebGPU content loaded into …8.1
- CVE-2026-22167Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-22168OpenClaw versions prior to 2026.2.21 contain an approval-int…8.8
- CVE-2026-2217A vulnerability was found in itsourcecode Event Management S…9.8
- CVE-2026-22170OpenClaw versions prior to 2026.2.22 with the optional BlueB…6.5
- CVE-2026-22171OpenClaw versions prior to 2026.2.19 contain a path traversa…9.1
- CVE-2026-22172OpenClaw versions prior to 2026.3.12 contain an authorizatio…9.9
- CVE-2026-22173Rejected reason: This CVE ID has been rejected.
- CVE-2026-22174OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-r…6.8
Are you affected by CVE-2026-22169?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
