Executive brief
OpenClaw, a tool for managing automated workflows and integrations, contains a security flaw in its MCP loopback feature. This vulnerability allows users with low-level access to bypass security restrictions and run powerful administrative tools intended only for the system owner. An attacker could use this to gain unauthorized control over the system, modify sensitive data, or disrupt operations.
Technical details
An authorization bypass vulnerability exists in OpenClaw's MCP loopback feature due to improper permission assignment (CWE-732) and missing authorization checks (CWE-862). The flaw allows a remote attacker with low privileges to bypass configured input path restrictions and execute tools normally reserved for the system owner. This can lead to unauthorized persistence and execution of administrative actions. The vulnerability is reachable over the network if the MCP loopback feature is enabled. A fix is available in version 2026.6.6, and users are advised to restrict the feature to trusted operators or disable it until patched.
Affected products
- OpenClaw OpenClaw >= 2026.5.20, < 2026.6.6
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-13: disclosed: NVD publication date
- 2026-06-30: patched: Version 2026.6.6 released