A vulnerability classified as problematic was found in OpenClaw up to 2026.2.21 . Affected is an unknown function of the file /echo . Executing a manipulation can lead to untrusted search path. This vulnerability appears as CVE-2026-32016 . The attack requires local access. There is no available exploit. Upgrading the affected component is advised.