Junglewise Threat Intelligence

OpenClaw incorrect authorization in native command handling

Severity: high · CVSS 7.2 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing command gateways, contains a security flaw where certain administrative commands can be executed by unauthorized users. If the native command feature is enabled, an attacker with basic access could bypass security policies to run commands intended only for the system owner. This could lead to unauthorized system changes or access to sensitive operations depending on how the gateway is configured.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's native command handling component. In affected versions, the system fails to properly enforce owner-only command policies when a sender triggers native command authorization. An attacker with 'Low' privileges can exploit this over a network to execute administrative commands that should be restricted to the owner. The vulnerability is present in the npm package 'openclaw' versions up to 2026.5.5 and is resolved in version 2026.5.6.

Affected products

  • openclaw openclaw <= 2026.5.5

Timeline

  • 2026-05-28: disclosed
  • 2026-07-02: advisory
  • 2026-05-28: patched: Date of initial report/patch activity mentioned in metadata

References

Related threats