SB2026052911 - Multiple vulnerabilities in OpenClaw



SB2026052911 - Multiple vulnerabilities in OpenClaw

Published: May 29, 2026 Updated: June 30, 2026

Security Bulletin ID SB2026052911
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Authentication Bypass by Spoofing (CVE-ID: N/A)

CWE-ID: CWE-290 - Authentication Bypass by Spoofing

CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to obtain a durable admin-capable device token.

The vulnerability exists due to authentication bypass by spoofing in the Control UI pairing path when processing locality information during pairing. A remote user can spoof locality information to obtain a durable admin-capable device token.

This issue is limited to LAN or shared-token Control UI deployments where the caller already has the network and authentication foothold needed to reach the pairing path.


2) Inclusion of Functionality from Untrusted Control Sphere (CVE-ID: N/A)

CWE-ID: CWE-829 - Inclusion of Functionality from Untrusted Control Sphere

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute or persist actions beyond the caller's intended authorization.

The vulnerability exists due to inclusion of functionality from untrusted control sphere in setup-mode discovery workspace plugins when processing a configured input path or lower-trust caller-controlled workspace input. A remote attacker can provide a crafted workspace plugin path or plugin input to execute or persist actions beyond the caller's intended authorization.

Only instances where the affected feature is enabled and reachable are vulnerable, and user interaction is required.


Remediation

Install update from vendor's website.