CVE-2026-27486

MEDIUM

OpenClaw CLI <2026.2.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw process. On shared hosts, unrelated processes can be terminated if they match the pattern. The CLI runner cleanup helpers can kill processes matched by command-line patterns without validating process ownership. This issue has been fixed in version 2026.2.14.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 5.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-283
Status published
Products (2)
npm/openclaw 0 - 2026.2.14npm
openclaw/openclaw < 2026.2.14
Published Feb 21, 2026
Tracked Since Feb 21, 2026