SB2026052907 - Multiple vulnerabilities in OpenClaw
Published: May 29, 2026 Updated: June 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the message read action when handling message read requests with the affected feature enabled and reachable. A remote user can request messages from a channel without the normal channel allowlist check to disclose sensitive information.
Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
2) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authorization checks and perform unauthorized actions.
The vulnerability exists due to improper access control in the browser act route when handling current-tab URL checks. A remote user can invoke the affected route through a lower-trust caller or configured input path to bypass authorization checks and perform unauthorized actions.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.
Remediation
Install update from vendor's website.