Junglewise Threat Intelligence

OpenClaw missing authorization in focus command

Severity: medium · CVSS 5.5 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and automation tool, contains a flaw where certain commands do not properly check a user's permissions. An authenticated user could bypass intended restrictions to change the system's focus state, potentially leading to unauthorized operations. This could allow a low-privileged user to interfere with tasks or configurations they should not be able to access.

Technical details

A missing authorization vulnerability (CWE-862) exists in OpenClaw versions prior to 2026.4.25. The 'focus' command fails to properly enforce 'controlScope' checks, allowing authenticated callers to execute the command outside of their intended authority. An attacker with local access and low privileges can trigger this command to manipulate the focus state, which may lead to further unauthorized operations depending on the specific gateway configuration and trust levels of the input. The issue is resolved in version 2026.4.25.

Affected products

  • OpenClaw openclaw < 2026.4.25

Timeline

  • 2026-05-28: advisory: Original advisory GHSA-mpc8-jxjh-qpgh published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53850
  • 2026-06-18: other: Duplicate advisory GHSA-gw2c-6hcg-5g52 withdrawn

References

Related threats