Privilege Escalation Vulnerability in OpenClaw Affected by Wildcard Inheritance
CVE-2026-53854

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-53854?

OpenClaw versions before 2026.4.25 contain a vulnerability that allows for privilege escalation due to inadequate command authentication in internal and webchat channels. This flaw permits attackers to exploit commands across different channel boundaries, enabling them to inherit wildcard ownerAllowFrom states improperly. Consequently, unauthorized users might gain elevated access, bypassing established access controls and executing commands with owner-level privileges outside their intended scopes.

Affected Version(s)

OpenClaw 0 < 2026.4.25

OpenClaw 2026.4.25

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
qclawer
.