Insecure File Permissions in OpenClaw Config Recovery
CVE-2026-53856

5.7MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-53856?

OpenClaw prior to version 2026.4.24 is susceptible to an insecure file permissions issue within its configuration recovery process. This vulnerability allows local attackers, particularly on shared hosting environments, to exploit the recovery path. As a result, they can access the restored OpenClaw.json file, potentially exposing sensitive configuration data that should remain protected. It is crucial for users to upgrade to the latest version to mitigate this security risk.

Affected Version(s)

OpenClaw 2026.4.23 < 2026.4.24

OpenClaw 2026.4.24

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kaze310
.