PT-2026-49780 · Openclaw · Openclaw

·

CVE-2026-53863

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.25
Description An input validation issue exists in tool group policy callers that accept unvalidated group IDs. An attacker capable of supplying a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, which may lead to the bypass of intended access controls. The practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Recommendations Update to version 2026.4.25. Avoid exposing group-policy controlled tools to untrusted senders. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the affected feature when it is not needed.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53863
GHSA-8WMM-344F-MPJG
GHSA-985F-72MJ-8GF7

Affected Products

Openclaw