CVE-2026-53863: Openclaw

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, potentially bypassing intended access controls.

Affected products

  • Openclaw Openclaw: before 2026.4.25 (fixed in 2026.4.25); version 2026.4.25 only

Published 2026-06-16. Last modified 2026-06-17.