CVE-2026-53818
Received Received - Intake
Authorization Bypass in OpenClaw MCP Loopback Feature

Publication date: 2026-06-11

Last updated on: 2026-06-11

Assigner: VulnCheck

Description
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-11
Last Modified
2026-06-11
Generated
2026-06-12
AI Q&A
2026-06-12
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.4.24 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in OpenClaw versions before 2026.4.24 and involves an authorization bypass in the MCP loopback feature. It allows non-owner users to bypass owner-only tool policies and hooks that normally restrict access. Attackers can exploit this loopback path to execute tools that should only be accessible to the owner when the feature is enabled and reachable.

Impact Analysis

The impact of this vulnerability is that unauthorized users with limited privileges can gain access to restricted tools and perform actions that are normally reserved for the owner. This can lead to unauthorized execution of sensitive operations, potentially compromising system integrity and security.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53818. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart