Executive brief
OpenClaw is a gateway and proxy management tool. A security flaw in versions prior to 2026.5.18 allows a local user on the same server to bypass security checks by forging identity information that the system normally only trusts from a secure proxy. This could allow an unauthorized person to impersonate an administrator, potentially leading to full control over the system and its data.
Technical details
OpenClaw fails to properly validate identity headers when configured with a trusted proxy on the same host. An attacker with local access to the proxy-facing Gateway port can craft and inject forged identity headers that the application incorrectly trusts as coming from a verified source. This vulnerability (CWE-290) allows the attacker to assume the identity of a privileged operator, leading to unauthorized access and potential privilege escalation. The issue is resolved in version 2026.5.18; users are advised to upgrade or restrict direct access to the Gateway port using firewall rules.
Affected products
- OpenClaw OpenClaw < 2026.5.18
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD