PT-2026-49761 · Openclaw · Openclaw

·

CVE-2026-53844

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.29
Description A session visibility check bypass exists in the shared memory search of the memory-wiki feature. This allows authenticated callers to skip session visibility guards on the search path, enabling them to retrieve memory entries that should not be visible to their session without proper authorization.
Recommendations Update to version 2026.4.29. Limit shared memory search to trusted operators. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the shared memory search feature when it is not needed.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53844
GHSA-6JM4-83G2-35GV
GHSA-72FW-CQH5-F324

Affected Products

Openclaw