Exec Allowlist Bypass in OpenClaw Affects Authenticated Operators
CVE-2026-53848

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-53848?

OpenClaw prior to version 2026.5.26 is vulnerable to an exec allowlist bypass, which enables authenticated users to execute unintended operations beyond the intended command scope. This occurs when attackers exploit transparent command wrappers to craft command requests that avoid standard allowlist checks, potentially leading to unauthorized command execution. This vulnerability poses significant risks if left unaddressed, allowing for possible misuse of system commands.

Affected Version(s)

OpenClaw 0 < 2026.5.26

OpenClaw 2026.5.26

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chinmohan Nayak (@nayakchinmohan)
.