Junglewise Threat Intelligence

OpenClaw privilege escalation in Active Memory write scope

Severity: medium · CVSS 5.4 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway management tool, contains a flaw where users with basic write permissions can bypass security restrictions to modify global system settings. Normally, these sensitive changes require administrative-level access. An attacker with a low-privileged account could exploit this to change how the gateway operates, potentially leading to unauthorized configuration changes or service disruption.

Technical details

A privilege escalation vulnerability exists in OpenClaw versions prior to 2026.5.6 due to insufficient scope validation in the Active Memory write component. The root cause is an 'Incorrect Privilege Assignment' (CWE-266) where the system fails to verify if a caller has 'operator.admin' privileges before allowing mutations to global configuration via the 'operator.write' scope. An authenticated attacker with network access and low-level write permissions can exploit this to apply unauthorized global configuration changes. The issue is resolved in version 2026.5.6.

Affected products

  • OpenClaw openclaw < 2026.5.6

Timeline

  • 2026-05-28: advisory: Original advisory GHSA-x629-46cc-7xgw published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53847
  • 2026-06-18: other: Duplicate advisory GHSA-58wc-8wrv-xp9j withdrawn

References

Related threats