Junglewise Threat Intelligence

CVE-2026-53847: OpenClaw privilege escalation in Active Memory write scope

CVE-2026-53847 · Severity: medium · CVSS 5.4 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a software package used for managing gateway operations and plugins. A security flaw in the Active Memory feature allows users with basic write permissions to modify global system settings that should normally be restricted to administrators. This could allow an authorized but low-privileged user to change how the system is configured, potentially leading to unauthorized operational changes or service disruptions.

Technical details

An incorrect privilege assignment (CWE-266) exists in OpenClaw's Active Memory feature. In affected versions, a Gateway caller possessing 'operator.write' permissions can execute commands that mutate the global configuration, a capability that should be restricted to 'operator.admin' users. The vulnerability is reachable over the network if the Active Memory feature is enabled. An attacker with low-level authenticated access can exploit this to escalate their privileges regarding system configuration. The issue is addressed in version 2026.5.6.

Affected products

  • openclaw openclaw <= 2026.5.5

Timeline

  • 2026-05-28: disclosed: Initial disclosure by researcher
  • 2026-06-18: advisory: GitHub Advisory published
  • 2026-05-28: patched: Version 2026.5.6 released

References

Related threats