CVE-2026-32973 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 29, 2026
OpenClaw - Command Injection
Overview
OpenClaw < 2026.3.11 contains a command injection caused by improper normalization of exec allowlist patterns with lowercasing and glob matching, letting attackers execute unintended commands or paths, exploit requires crafted input with ? wildcard.
Severity & Score
Impact
Attackers can execute arbitrary commands or paths not intended by operators, potentially leading to full system compromise.
Mitigation
Update to version 2026.3.11 or later.
References
Social Media Activity(6 posts)
š“ CVE-2026-32973 - Critical (9.8) OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard mat... š https://www.thehackerwire.com/vulnerability/CVE-2026-32973/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-32973 - Critical (9.8) OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard mat... š https://www.thehackerwire.com/vulnerability/CVE-2026-32973/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-32973 - Critical (9.8) OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard mat... š https://www.thehackerwire.com/vulnerability/CVE-2026-32973/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-32973 - Critical (9.8) OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard mat... š https://www.thehackerwire.com/vulnerability/CVE-2026-32973/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-32973 - Critical (9.8) OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard mat... š https://www.thehackerwire.com/vulnerability/CVE-2026-32973/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-32973 - Critical (9.8) OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard mat... š https://www.thehackerwire.com/vulnerability/CVE-2026-32973/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-32973
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 6
CWE
- CWE-625
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H