Insecure File Permissions in OpenClaw Config Recovery
CVE-2026-53856
5.7MEDIUM
What is CVE-2026-53856?
OpenClaw prior to version 2026.4.24 is susceptible to an insecure file permissions issue within its configuration recovery process. This vulnerability allows local attackers, particularly on shared hosting environments, to exploit the recovery path. As a result, they can access the restored OpenClaw.json file, potentially exposing sensitive configuration data that should remain protected. It is crucial for users to upgrade to the latest version to mitigate this security risk.
Affected Version(s)
OpenClaw 2026.4.23 < 2026.4.24
OpenClaw 2026.4.24
