CVE 4.3 MEDIUM

OpenClaw: Process Safety – Unvalidated PID Kill via SIGKILL in Process Cleanup_CVE-2026-27486

4.3 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H

Description

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw process. On shared hosts, unrelated processes can be terminated if they match the pattern. The CLI runner cleanup helpers can kill processes matched by command-line patterns without validating process ownership. This issue has been fixed in version 2026.2.14.

Basic Information

ID CVE-2026-27486
Source GitHub_M
Published Feb 21, 2026 at 09:32

Affected Product

Vendor openclaw
Product openclaw
Version < 2026.2.14
Affected Versions openclaw openclaw < 2026.2.14

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.