Junglewise Threat Intelligence

OpenClaw authorization bypass in shared memory search

Severity: medium · CVSS 6.5 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a software package used for managing shared memory and data search, contains a security flaw that could allow users to see information they are not authorized to access. An authenticated user could bypass internal visibility checks to view sensitive memory entries belonging to other sessions. This could lead to the exposure of private data or internal system information.

Technical details

A missing authorization vulnerability (CWE-862) exists in OpenClaw's shared memory search path. In affected versions prior to 2026.4.29, the system fails to properly enforce session visibility guards during search operations. An authenticated attacker with network access can exploit this flaw to retrieve memory entries that should be restricted to other sessions. The vulnerability is specifically located within the memory-wiki shared search component. Users are advised to upgrade to version 2026.4.29 or later to remediate the issue.

Affected products

  • OpenClaw OpenClaw < 2026.4.29

Timeline

  • 2026-05-28: advisory: Original GHSA-72fw-cqh5-f324 published
  • 2026-06-16: disclosed: CVE-2026-53844 published
  • 2026-06-18: other: Duplicate advisory GHSA-6jm4-83g2-35gv withdrawn

References

Related threats