VYPR
High severity8.3NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026

CVE-2026-53814

CVE-2026-53814

Description

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron state modifications.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OpenClaw/Openclawinferred3 versions
    <2026.5.20+ 2 more
    • (no CPE)range: <2026.5.20
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: <2026.5.20
    • (no CPE)range: <2026.5.20

Patches

Vulnerability mechanics

References

2

News mentions

1