Privilege Escalation Vulnerability in OpenClaw Affected by Wildcard Inheritance
CVE-2026-53854
6MEDIUM
What is CVE-2026-53854?
OpenClaw versions before 2026.4.25 contain a vulnerability that allows for privilege escalation due to inadequate command authentication in internal and webchat channels. This flaw permits attackers to exploit commands across different channel boundaries, enabling them to inherit wildcard ownerAllowFrom states improperly. Consequently, unauthorized users might gain elevated access, bypassing established access controls and executing commands with owner-level privileges outside their intended scopes.
Affected Version(s)
OpenClaw 0 < 2026.4.25
OpenClaw 2026.4.25
