Junglewise Threat Intelligence

CVE-2026-53844: OpenClaw session visibility check bypass in shared memory search

CVE-2026-53844 · Severity: medium · CVSS 6.5 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an open-source gateway and plugin system. A vulnerability in its 'memory-wiki' feature allows users to bypass security checks when searching shared memory. This could allow an unauthorized person to view sensitive data or memory entries that should be restricted to other sessions or users.

Technical details

A missing authorization vulnerability (CWE-862) exists in the memory-wiki shared search component of OpenClaw. In affected versions, the search path fails to properly enforce session visibility guards. An authenticated attacker with network access and low privileges can exploit this to retrieve memory entries that should be restricted to other sessions. The vulnerability is specific to configurations where the shared memory search feature is enabled and reachable by lower-trust inputs. A fix is available in version 2026.4.29.

Affected products

  • OpenClaw openclaw <= 2026.4.27

Timeline

  • 2026-05-28: disclosed
  • 2026-06-18: advisory: GitHub Advisory published
  • 2026-04-29: patched

References

Related threats