OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
CVE-2026-53818

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
11 June 2026

What is CVE-2026-53818?

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.

Affected Version(s)

OpenClaw 0 < 2026.4.24

OpenClaw 2026.4.24

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
qclawer
qclawer
.