CVE-2026-53863: Openclaw
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, potentially bypassing intended access controls.
Affected products
- Openclaw Openclaw: before 2026.4.25 (fixed in 2026.4.25); version 2026.4.25 only
Published 2026-06-16. Last modified 2026-06-17.