Medium severity6.5NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026
CVE-2026-53854
CVE-2026-53854
Description
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope, potentially bypassing access controls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.4.25 | 2026.4.25 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-4hpg-mp64-x7xqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53854ghsaADVISORY
- github.com/openclaw/openclaw/security/advisories/GHSA-4hpg-mp64-x7xqnvdWEB
- www.vulncheck.com/advisories/openclaw-privilege-escalation-via-ownerallowfrom-wildcard-inheritance-in-internal-webchat-commandsnvdWEB
News mentions
1- OpenClaw: 25 CVEs Disclosed in a Single Day — Allowlist Bypasses and Privilege Escalation DominateVypr Intelligence · Jun 16, 2026