A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.2.18 . The affected element is an unknown function of the file gateway.cmd of the component Environment Variable Handler . The manipulation results in os command injection. This vulnerability is cataloged as CVE-2026-22176 . The attack must be initiated from a local position. There is no exploit available. You should upgrade the affected component.