CVE-2026-53854
Received Received - Intake
Privilege Escalation in OpenClaw via Command Authentication Bypass

Publication date: 2026-06-16

Last updated on: 2026-06-16

Assigner: VulnCheck

Description
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope, potentially bypassing access controls.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-16
Last Modified
2026-06-16
Generated
2026-06-16
AI Q&A
2026-06-16
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.4.25 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in OpenClaw versions before 2026.4.25 and involves a flaw in internal and webchat command authentication.

Specifically, the issue allows senders to inherit a wildcard ownerAllowFrom state across different channel boundaries, meaning that commands intended to be restricted to certain channels can be executed with owner-level permissions in other channels.

Attackers can exploit this by sending commands on affected internal or webchat paths to perform owner-style command behavior outside the intended channel scope, potentially bypassing access controls.

Impact Analysis

The vulnerability can lead to privilege escalation, allowing attackers with low privileges to execute commands with owner-level permissions.

This can result in unauthorized actions being performed across channel boundaries, potentially compromising the integrity of the system.

The impact depends on the operator's configuration and whether lower-trust input can reach the affected paths.

There is no impact on confidentiality or availability, but the integrity of the system is at high risk.

Mitigation Strategies

To mitigate this vulnerability in OpenClaw versions before 2026.4.25, you should upgrade to version 2026.4.25 or later where the issue is patched.

  • Keep owner command allowlists explicit per channel.
  • Narrow channel and tool allowlists to limit access.
  • Avoid shared Gateways between untrusted users.
  • Disable the affected feature when it is not needed.
Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53854. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart