Low severity3.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-53809
CVE-2026-53809
Description
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-p39j-x9h5-q66mnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-provider-alias-confusion-in-embedded-runner-policynvdThird Party Advisory
News mentions
1- OpenClaw: 14 Vulnerabilities Disclosed in Single Batch, Including Code Execution and Privilege EscalationVypr Intelligence · Jun 11, 2026