CVE-2026-53817
- EPSS 0.31%
- Veröffentlicht 11.06.2026 20:09:38
- Zuletzt bearbeitet 12.06.2026 20:08:17
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient lo...
CVE-2026-53816
- EPSS 0.34%
- Veröffentlicht 11.06.2026 20:09:15
- Zuletzt bearbeitet 12.06.2026 20:08:26
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send cr...
CVE-2026-53815
- EPSS 0.22%
- Veröffentlicht 11.06.2026 20:08:52
- Zuletzt bearbeitet 12.06.2026 19:24:55
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation i...
CVE-2026-53814
- EPSS 0.28%
- Veröffentlicht 11.06.2026 20:08:31
- Zuletzt bearbeitet 12.06.2026 19:25:09
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hook...
CVE-2026-53813
- EPSS 0.12%
- Veröffentlicht 11.06.2026 20:08:11
- Zuletzt bearbeitet 12.06.2026 19:25:15
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from uninten...
CVE-2026-53812
- EPSS 0.25%
- Veröffentlicht 11.06.2026 20:07:51
- Zuletzt bearbeitet 12.06.2026 19:25:23
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to pri...
CVE-2026-53811
- EPSS 0.31%
- Veröffentlicht 11.06.2026 20:07:29
- Zuletzt bearbeitet 12.06.2026 19:32:22
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display name...
CVE-2026-53810
- EPSS 0.42%
- Veröffentlicht 11.06.2026 20:07:04
- Zuletzt bearbeitet 12.06.2026 19:32:38
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load pl...
CVE-2026-53809
- EPSS 0.09%
- Veröffentlicht 11.06.2026 20:06:43
- Zuletzt bearbeitet 12.06.2026 19:32:51
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select...
CVE-2026-53808
- EPSS 0.19%
- Veröffentlicht 11.06.2026 20:06:14
- Zuletzt bearbeitet 12.06.2026 19:32:56
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affec...