CVE-2026-53848: Openclaw
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers to perform unintended operations.
Affected products
- Openclaw Openclaw: before 2026.5.26 (fixed in 2026.5.26); version 2026.5.26 only
Published 2026-06-16. Last modified 2026-06-17.