These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands. This vulnerability allows lower-trust callers to execute or persist actions beyond their intended authorization. The vulnerability is caused by a lack of proper authorization in the plugin install commands of OpenClaw. Attackers can exploit misconfigured input paths or enabled features to e [truncated]
OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. This allows lower-trust callers or configured input paths to execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is f [truncated]
CVE-2026-62192 is an authorization bypass vulnerability in OpenClaw versions 2026.6.6 before 2026.6.9. The vulnerability allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations. This vulnerability has a high CVSS score of 7.2 and is classified as H [truncated]
CVE-2026-62191 is an authorization bypass vulnerability in OpenClaw versions 2026.6.6 before 2026.6.9. The vulnerability allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable. This vulnerability has a high seve [truncated]
CVE-2026-62189 is a high-severity vulnerability in OpenClaw versions before 2026.6.9, caused by a symlink following issue in the mirror sync feature. This vulnerability allows lower-trust callers to perform actions requiring stronger authorization, potentially leading to bypass of policy checks and authorization boundaries. The vulnerability has significant implications for users of OpenClaw, particularly [truncated]
CVE-2026-62188 is an incorrect authorization vulnerability in OpenClaw @openclaw/feishu versions 2026.6.6 and earlier. The Feishu permission tools could ignore per-account disablement settings when the affected feature is enabled and reachable. A lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in versi [truncated]
The OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 are vulnerable to an authorization bypass. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. This vulnerability could allow attackers to perform actions that sho [truncated]
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. This vulnerability can be exploited by attackers to bypass admin authorization policies and execute restricted operations. The vulnerability has a high severity with a CVSS score of 7.2. Users a [truncated]
CVE-2026-53866 is a HIGH-severity vulnerability in OpenClaw, a software that contains an allowlist bypass vulnerability in shell inline-command parsing. This vulnerability, with a CVSS score of 7.6, allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell conte [truncated]
CVE-2026-53865 is a HIGH-severity vulnerability in OpenClaw, a software that is vulnerable to path traversal attacks. The vulnerability, which has a CVSS score of 7.2, allows workspace-derived service paths to influence trash command selection, enabling attackers to execute unintended local executables from operator-unintended paths during maintenance operations.
CVE-2026-53864 is a HIGH-severity vulnerability in OpenClaw, a software that failed to properly sanitize environment variables, allowing attackers to influence child processes or coverage output paths. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-53863 is a MEDIUM severity vulnerability in OpenClaw, a tool that contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. This vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-53862 is a low-severity vulnerability in OpenClaw, a software that enables secure pairing and authentication. The vulnerability, disclosed on June 16, 2026, allows an attacker to replay bootstrap tokens before approval, potentially escalating pairing authority beyond intended scope limits.
CVE-2026-53861 is a MEDIUM severity vulnerability in OpenClaw before version 2026.5.6. The vulnerability is caused by an allowlist bypass in the macOS Swift exec feature, which misses combined POSIX inline-command flags. This allows attackers to execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator [truncated]
CVE-2026-53860 is a low-severity vulnerability in OpenClaw, specifically in the BlueBubbles component. The vulnerability allows participants to bypass sender policy by matching allowlist entries through conversation metadata rather than stable sender identity. This could potentially allow attackers to influence conversation-level identifiers and receive agent responses intended for configured senders, byp [truncated]
CVE-2026-53859 is a MEDIUM-severity vulnerability in OpenClaw, a software that contains a hostname validation vulnerability. This vulnerability allows attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. As a result, attackers can reach destinations that operators intended to block through hostname policies.
CVE-2026-53858 is a HIGH severity vulnerability in OpenClaw before version 2026.5.2. The vulnerability is caused by an environment variable injection issue where the workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. This allows attackers to manipulate the STATE_DIRECTORY variable to load runtime dependencies from unintended local paths, potentially executing malicious code d [truncated]
CVE-2026-53857 is a HIGH-severity vulnerability in OpenClaw, a software that contains a policy enforcement issue. The vulnerability has a CVSS score of 8.6. The issue arises from OpenClaw's handling of Zalo contacts with mutable display metadata, which could allow an attacker to receive agent responses intended for different Zalo identities when the feature is enabled. This vulnerability was published on [truncated]
CVE-2026-53856 is a MEDIUM-severity vulnerability in OpenClaw, a software that contains an insecure file permissions vulnerability in its config recovery feature. The vulnerability allows local attackers on shared hosts to read sensitive configuration data by exploiting the recovery path to access the restored config file.
CVE-2026-53855 is a HIGH-severity vulnerability in OpenClaw, a software that enables users to manage and automate various tasks. The vulnerability, which has a CVSS score of 7.6, allows authenticated operators to bypass strict allowlist checks via shell positional parameters, potentially enabling the execution of unapproved shell-provided content.
CVE-2026-53854 is a medium-severity privilege escalation vulnerability in OpenClaw before version 2026.4.25. The vulnerability allows senders to inherit the 'ownerAllowFrom' wildcard state across channel boundaries, potentially bypassing access controls. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope.
CVE-2026-53853 is a HIGH-severity vulnerability in OpenClaw, a software that was vulnerable to an argument pattern validation bypass in its exec allowlist. The vulnerability, which was published on 2026-06-16T19:17:02.650Z and modified on 2026-06-16T20:42:46.200Z, allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. This could potentially enable unauthor [truncated]
CVE-2026-53852 is a scope containment bypass vulnerability in OpenClaw before version 2026.4.25. The vulnerability occurs in the device re-pairing process and allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. This can be exploited by attackers to send re-pairing requests with empty scope sets, effectively skipping containment guards and r [truncated]
CVE-2026-53851 is a MEDIUM-severity vulnerability (CVSS Score: 6.3) in OpenClaw, a software that appears to be related to automation or workflow management, potentially involving Slack integration. The issue, publicly disclosed on 2026-06-16, allows attackers to bypass notification settings for Slack reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input.
CVE-2026-53850 is a MEDIUM-severity vulnerability in OpenClaw, a software that was vulnerable to a control scope enforcement bypass in its focus command feature. The vulnerability, which has a CVSS score of 6.8, allows authenticated callers to execute the focus command without proper authorization checks, potentially enabling unauthorized operations depending on gateway configuration and input trust level [truncated]
CVE-2026-53849 is a HIGH-severity vulnerability in OpenClaw, a software that failed to properly validate Discord account identities. The vulnerability exists in versions prior to 2026.5.7 and is caused by the allowFrom feature using mutable display names instead of immutable user IDs. This oversight allows attackers with Discord accounts to change their display name to match a policy entry and gain unauth [truncated]
CVE-2026-53848 is a low-severity vulnerability in OpenClaw before version 2026.5.26 that allows authenticated operators to bypass the exec allowlist and execute wrapper-level side effects outside allowlisted command intent. The vulnerability has a CVSS score of 2.3 and is classified as CWE-184. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers [truncated]
CVE-2026-53847 is a medium-severity privilege escalation vulnerability in OpenClaw before 2026.5.6. The vulnerability allows Gateway operators with operator.write access to modify global configuration without requiring operator.admin privileges. This is possible due to insufficient scope validation in the Active Memory write scope, enabling attackers to apply unauthorized configuration changes beyond the [truncated]
CVE-2026-53846 is a HIGH-severity vulnerability in OpenClaw, a software that was vulnerable to a path traversal issue. The vulnerability, which has a CVSS score of 7, was published on 2026-06-16T19:17:01.653Z and last modified on 2026-06-16T20:42:46.200Z. The issue allows attackers with workspace access to execute unintended local package-manager executables during dependency setup, potentially compromisi [truncated]
CVE-2026-53845 is a low-severity vulnerability (CVSS Score: 2.3) affecting OpenClaw before version 2026.5.6. The vulnerability is caused by a hook bypass issue where skill commands routed through the affected dispatch path skip before-tool-calls hook coverage. This allows attackers to bypass hook-based auditing and policy enforcement mechanisms by sending skill commands through the vulnerable dispatch path.