SB2026052907 - Multiple vulnerabilities in OpenClaw



SB2026052907 - Multiple vulnerabilities in OpenClaw

Published: May 29, 2026 Updated: June 30, 2026

Security Bulletin ID SB2026052907
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the message read action when handling message read requests with the affected feature enabled and reachable. A remote user can request messages from a channel without the normal channel allowlist check to disclose sensitive information.

Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.


2) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass authorization checks and perform unauthorized actions.

The vulnerability exists due to improper access control in the browser act route when handling current-tab URL checks. A remote user can invoke the affected route through a lower-trust caller or configured input path to bypass authorization checks and perform unauthorized actions.

Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.


Remediation

Install update from vendor's website.