PT-2026-49764 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53847

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.write access to modify global configuration without requiring operator.admin privileges. Attackers with operator.write access can exploit insufficient scope validation to apply unauthorized configuration changes beyond the intended write scope.

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2026-53847

Affected Products

Openclaw