PT-2026-49771 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53854

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope, potentially bypassing access controls.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-53854

Affected Products

Openclaw