OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-rggc-m335-3wvj | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-identity-header-forgery-via-trusted-proxy-configuration | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-12 22:16
Updated : 2026-07-23 09:10
NVD link : CVE-2026-53832
Mitre link : CVE-2026-53832
CVE.ORG link : CVE-2026-53832
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-290
Authentication Bypass by Spoofing
