← العودة للجدول
CVE-2026-28391
CVE-2026-28391 — OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe me
📅 2026-03-05
🔴 Critical 🔥 No NVD Exploit Microsoft CVSS 9.8 🎯 EPSS 0.08%

📋 الوصف الكامل

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can craft command strings with shell metacharacters like & or %...% to execute unapproved commands beyond the allowlisted operations.

💻 الأنظمة المتأثرة

Microsoft Windows

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-28391

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2026.2.2

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←