📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Financial Services / Gaming HIGH 2h Global vulnerability Telecommunications / Enterprise Infrastructure CRITICAL 2h Global vulnerability Information Technology CRITICAL 2h Global malware General / Multi-sector CRITICAL 3h Global general Sports & Events HIGH 3h Global insider Governance & Ethics MEDIUM 4h Global vulnerability Technology and AI Systems HIGH 6h Global vulnerability Technology, Media, Broadcasting CRITICAL 6h Global vulnerability Government and Critical Infrastructure CRITICAL 6h Global supply_chain Artificial Intelligence and Technology HIGH 7h Global data_breach Financial Services / Gaming HIGH 2h Global vulnerability Telecommunications / Enterprise Infrastructure CRITICAL 2h Global vulnerability Information Technology CRITICAL 2h Global malware General / Multi-sector CRITICAL 3h Global general Sports & Events HIGH 3h Global insider Governance & Ethics MEDIUM 4h Global vulnerability Technology and AI Systems HIGH 6h Global vulnerability Technology, Media, Broadcasting CRITICAL 6h Global vulnerability Government and Critical Infrastructure CRITICAL 6h Global supply_chain Artificial Intelligence and Technology HIGH 7h Global data_breach Financial Services / Gaming HIGH 2h Global vulnerability Telecommunications / Enterprise Infrastructure CRITICAL 2h Global vulnerability Information Technology CRITICAL 2h Global malware General / Multi-sector CRITICAL 3h Global general Sports & Events HIGH 3h Global insider Governance & Ethics MEDIUM 4h Global vulnerability Technology and AI Systems HIGH 6h Global vulnerability Technology, Media, Broadcasting CRITICAL 6h Global vulnerability Government and Critical Infrastructure CRITICAL 6h Global supply_chain Artificial Intelligence and Technology HIGH 7h
Vulnerabilities

CVE-2026-32043

Medium
OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at exec
CWE-367 — Weakness Type
Published: Mar 21, 2026  ·  Modified: Mar 23, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a symlinked cwd between approval and execution to bypass command execution restrictions and execute arbitrary commands on node hosts.

🤖 AI Executive Summary

OpenClaw versions before 2026.2.25 contain a time-of-check-time-of-use (TOCTOU) vulnerability in the approval-bound system.run execution mechanism. Attackers can manipulate symlinked working directories between approval and execution phases to bypass command execution restrictions and achieve arbitrary code execution on node hosts. This vulnerability poses a significant risk to organizations using OpenClaw for infrastructure automation and command execution workflows.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 12, 2026 22:03
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi organizations in government IT infrastructure, financial services automation, and energy sector operations that utilize OpenClaw for infrastructure-as-code and automated command execution. High-risk sectors include: (1) ARAMCO and energy companies using OpenClaw for operational automation, (2) Banking sector (SAMA-regulated institutions) using it for backend infrastructure management, (3) Government agencies (NCA oversight) employing OpenClaw for system administration, (4) Telecom operators (STC, Mobily) using it for network automation. The TOCTOU vulnerability allows privilege escalation and lateral movement within critical infrastructure environments.
🏢 Affected Saudi Sectors
Government Banking and Financial Services Energy and Utilities Telecommunications Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all OpenClaw deployments in your environment and document versions currently in use
2. Restrict access to OpenClaw approval workflows to trusted administrators only
3. Implement file system monitoring on directories containing symlinks used in OpenClaw cwd parameters
4. Review approval logs for any suspicious cwd parameter changes or symlink manipulations

Patching Guidance:
1. Upgrade to OpenClaw version 2026.2.25 or later when available
2. Until patch is available, implement compensating controls:
- Use read-only file systems or immutable snapshots for cwd directories
- Implement SELinux or AppArmor policies to restrict symlink resolution in OpenClaw execution contexts
- Disable symlink support in cwd parameters if functionality permits

Compensating Controls:
1. Deploy file integrity monitoring (FIM) on all directories used as cwd parameters
2. Implement strict change control procedures requiring re-approval if cwd paths are modified
3. Use containerized execution environments with restricted file system access
4. Enable audit logging for all symlink creation/modification events

Detection Rules:
1. Alert on symlink creation/modification in directories used as OpenClaw cwd parameters
2. Monitor for approval records where cwd path differs from actual resolved path at execution time
3. Track execution of commands with unexpected working directories
4. Flag approval-to-execution time gaps exceeding normal thresholds
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع نشرات OpenClaw في بيئتك وتوثيق الإصدارات المستخدمة حالياً
2. قيد الوصول إلى سير عمل موافقة OpenClaw للمسؤولين الموثوقين فقط
3. طبق مراقبة نظام الملفات على المجلدات التي تحتوي على روابط رمزية المستخدمة في معاملات cwd
4. راجع سجلات الموافقة للكشف عن أي تغييرات مريبة في معاملات cwd أو تلاعب بالروابط الرمزية

إرشادات التصحيح:
1. قم بالترقية إلى إصدار OpenClaw 2026.2.25 أو أحدث عند توفره
2. حتى يتوفر التصحيح، طبق عناصر تحكم تعويضية:
- استخدم أنظمة ملفات للقراءة فقط أو لقطات ثابتة لمجلدات cwd
- طبق سياسات SELinux أو AppArmor لتقييد دقة الروابط الرمزية في سياقات تنفيذ OpenClaw
- عطل دعم الروابط الرمزية في معاملات cwd إن أمكن

عناصر التحكم التعويضية:
1. نشر مراقبة سلامة الملفات (FIM) على جميع المجلدات المستخدمة كمعاملات cwd
2. طبق إجراءات تحكم صارمة في التغيير تتطلب إعادة موافقة إذا تم تعديل مسارات cwd
3. استخدم بيئات التنفيذ المحتوية مع وصول نظام ملفات مقيد
4. فعّل تسجيل التدقيق لجميع أحداث إنشاء/تعديل الروابط الرمزية

قواعد الكشف:
1. تنبيهات عند إنشاء/تعديل الروابط الرمزية في المجلدات المستخدمة كمعاملات cwd
2. مراقبة سجلات الموافقة حيث يختلف مسار cwd عن المسار المحل الفعلي وقت التنفيذ
3. تتبع تنفيذ الأوامر مع مجلدات عمل غير متوقعة
4. وضع علم على فجوات الموافقة إلى التنفيذ التي تتجاوز الحدود الطبيعية
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies (approval bypass vulnerability) ECC 2024 A.12.4.1 - Event Logging (insufficient logging of symlink manipulation) ECC 2024 A.12.4.3 - Protection of Log Information (audit trail integrity) ECC 2024 A.14.2.1 - Change Management (inadequate change control in cwd resolution)
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Asset Management (inventory of vulnerable OpenClaw instances) SAMA CSF PR.AC-1 - Access Control (approval mechanism bypass) SAMA CSF DE.CM-1 - Detection and Analysis (monitoring symlink manipulation) SAMA CSF RS.MI-2 - Incident Response (containment of arbitrary code execution)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access Control (approval workflow integrity) ISO 27001:2022 A.8.1 - User Endpoint Devices (command execution restrictions) ISO 27001:2022 A.12.4.1 - Event Logging (TOCTOU detection) ISO 27001:2022 A.14.2.1 - Change of Information and Processing Facilities (cwd parameter validation)
🟣 PCI DSS v4.0.1
PCI DSS 3.2.1 - Strong Cryptography (if OpenClaw used in payment systems) PCI DSS 7.1 - Access Control (approval bypass impact) PCI DSS 10.2.1 - Audit Trails (insufficient logging of execution context changes)
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityH — High
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-367
Exploit No
Patch ✗ No
Published 2026-03-21
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-367
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.