PT-2026-49767 · Openclaw · Openclaw

·

CVE-2026-53850

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.25
Description A control scope enforcement bypass exists in the focus command. This allows authenticated callers to execute the command without proper authorization checks, enabling them to change the focus state outside of the intended caller authority. The practical impact depends on the gateway configuration and whether lower-trust input can reach the affected path.
Recommendations Update to version 2026.4.25. Restrict focus command access to trusted operators. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the focus command feature when it is not needed.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53850
GHSA-GW2C-6HCG-5G52
GHSA-MPC8-JXJH-QPGH

Affected Products

Openclaw