OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement
CVE-2026-53828
7.7HIGH
What is CVE-2026-53828?
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, potentially executing privileged commands from unauthorized users.
Affected Version(s)
OpenClaw 0 < 2026.5.6
OpenClaw 2026.5.6
