Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
CVE coverage

CVE-2026-101880

CVSS 8.8 no coverage
View on NVD →
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.

Detection rules

No detection found — yet
None of Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata currently has a rule referencing CVE-2026-101880.