Junglewise Threat Intelligence

CVE-2026-53821: OpenClaw privilege escalation in trusted-proxy Control UI WebSocket

CVE-2026-53821 · Severity: high · CVSS 8.8 · Published 2026-06-12

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway management platform, contains a flaw in how it handles WebSocket connections when configured with 'trusted-proxy' authentication. An attacker with low-level access can bypass security checks to gain administrative privileges. This allows them to execute restricted commands, potentially leading to full control over the gateway and its operations.

Technical details

A missing authorization check (CWE-862) exists in OpenClaw's WebSocket implementation when 'gateway.auth.mode' is set to 'trusted-proxy'. The application incorrectly accepts client-declared operator scopes before they are bound to a server-approved pairing or trusted-proxy authorization baseline. A remote attacker with low privileges can present a fresh, unpaired device identity with elevated requested scopes to obtain 'operator.admin' authority. This authority can be used to execute admin-gated Gateway RPCs on the live WebSocket connection. The vulnerability is patched in version 2026.5.18.

Affected products

  • OpenClaw OpenClaw < 2026.5.18

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-05-28: patched: Version 2026.5.18 released
  • 2026-06-12: disclosed: CVE-2026-53821 published to NVD

References

Related threats