Junglewise Threat Intelligence

CVE-2026-53809: OpenClaw policy bypass in embedded runner policy

CVE-2026-53809 · Severity: low · CVSS 3.8 · Published 2026-06-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an automation platform that manages tool execution through a gateway. A security flaw in its embedded runner policy allows the system to be confused by provider aliases, potentially allowing tools to run with incorrect permissions. This could lead to unauthorized tool access or actions that bypass intended security restrictions.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's embedded runner where policy enforcement can be bypassed using provider aliases. When a request uses an alias, the system may validate the policy against the alias string rather than the canonical provider identity. This logic flaw allows for the selection of bundled tool access outside of the intended provider policy. The vulnerability requires local access with low privileges to exploit. A fix is available in version 2026.4.25.

Affected products

  • OpenClaw openclaw <= 2026.4.24

Timeline

  • 2026-05-28: disclosed
  • 2026-06-11: advisory: NVD publication
  • 2026-07-02: patched: GitHub Advisory published/updated

References

Related threats