Junglewise Threat Intelligence

OpenClaw privilege escalation in internal and webchat command auth

Severity: medium · CVSS 6.5 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and command platform, contains a flaw in how it handles permissions for internal and web-based chat commands. An attacker with basic access could trick the system into granting them administrative 'owner' privileges across different chat channels. This could allow unauthorized users to execute sensitive commands, potentially leading to unauthorized system modifications or a complete bypass of security controls.

Technical details

A privilege escalation vulnerability (CWE-863) exists in OpenClaw versions prior to 2026.4.25. The root cause is an incorrect authorization logic in the internal and webchat command authentication paths that allows a sender to inherit the 'ownerAllowFrom' wildcard state across channel boundaries. An authenticated attacker with low privileges can exploit this over the network by sending commands through affected paths to execute owner-level behaviors outside of their intended scope. This allows for the bypass of intended access controls and unauthorized integrity-impacting actions. The issue is resolved in version 2026.4.25.

Affected products

  • OpenClaw openclaw < 2026.4.25

Timeline

  • 2026-05-28: advisory: Original GHSA-4hpg-mp64-x7xq published
  • 2026-06-16: disclosed: NVD publication of CVE-2026-53854
  • 2026-06-18: other: Duplicate advisory GHSA-r2fx-hp6p-pgrm withdrawn

References

Related threats