Incorrect authorization in OpenClaw - #VU132698

 

Incorrect authorization in OpenClaw - #VU132698

Published: May 29, 2026


Vulnerability identifier: #VU132698
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute unintended shell operations.

The vulnerability exists due to incorrect authorization in the exec approval display and binding when handling oversized exec commands in the approval view. A remote user can create a pending host exec request with a command long enough to be truncated to execute unintended shell operations.

This affects deployments where exec approval is enabled, and user interaction is required because an approver must approve the request.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.5.18

External References

Related Security Bulletins