Exec Allowlist Bypass in OpenClaw Affects Authenticated Operators
CVE-2026-53848
2.3LOW
What is CVE-2026-53848?
OpenClaw prior to version 2026.5.26 is vulnerable to an exec allowlist bypass, which enables authenticated users to execute unintended operations beyond the intended command scope. This occurs when attackers exploit transparent command wrappers to craft command requests that avoid standard allowlist checks, potentially leading to unauthorized command execution. This vulnerability poses significant risks if left unaddressed, allowing for possible misuse of system commands.
Affected Version(s)
OpenClaw 0 < 2026.5.26
OpenClaw 2026.5.26
