OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-mpc8-jxjh-qpgh | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-control-scope-enforcement-bypass-in-focus-command | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-16 19:17
Updated : 2026-06-17 21:02
NVD link : CVE-2026-53850
Mitre link : CVE-2026-53850
CVE.ORG link : CVE-2026-53850
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-862
Missing Authorization
