Executive brief
OpenClaw is a software package used for configuration management. A security issue exists where the software's configuration recovery process sets incorrect file permissions on its settings file. This could allow other users on the same computer system to read sensitive configuration data, potentially leading to further unauthorized access or data exposure.
Technical details
OpenClaw version 2026.4.23 is vulnerable to incorrect permission assignment (CWE-732) during its configuration recovery process. When the software repairs or restores the 'openclaw.json' configuration file, it applies overly broad file system permissions. A local attacker with low privileges on a shared host can exploit this by reading the restored configuration file, which may contain sensitive data. The vulnerability is triggered specifically during the config recovery path. The issue is resolved in version 2026.4.24.
Affected products
- OpenClaw openclaw = 2026.4.23
Timeline
- 2026-05-28: advisory: Original GHSA-rwp6-7w3q-75fq published
- 2026-06-16: disclosed: CVE-2026-53856 published
- 2026-06-18: other: Duplicate advisory GHSA-vqj9-vhg4-27mg withdrawn