Incorrect default permissions in OpenClaw - #VU132732

 

Incorrect default permissions in OpenClaw - #VU132732

Published: May 29, 2026


Vulnerability identifier: #VU132732
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to incorrect default permissions in the config recovery feature when restoring configuration after repair. A local user can access a restored openclaw.json file with broader read permissions to disclose sensitive information.

Only configurations with the affected feature enabled and reachable are exposed.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.24

External References

Related Security Bulletins