Description
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
Severity (CVSS)
| Base score | 2.3 |
|---|---|
| Severity | Low |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-863 — Incorrect Authorization
Affected products
| Vendor | Product | Versions |
|---|---|---|
| OpenClaw | OpenClaw | 2026.5.12 to <2026.5.26; 2026.5.26 |
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-fh8v-vgcv-pwh4 (vendor-advisory)
- https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-allowfrom (third-party-advisory)
Generated from the official CVE List on 17 Jul 2026 07:01 UTC.