CVE-2026-53832: Openclaw

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.

Affected products

  • Openclaw Openclaw: before 2026.5.18 (fixed in 2026.5.18)

Published 2026-06-12. Last modified 2026-07-23.