OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.