Vulnerabilities
Vulnerable Software
Openclaw:  >> Openclaw  >> 2026.5.27  Security Vulnerabilities
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-07-13
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin authorization policies and execute restricted operations.
CVSS Score
7.2
EPSS Score
0.002
Published
2026-07-13
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.
CVSS Score
8.4
EPSS Score
0.002
Published
2026-07-08


Contact Us

Shodan ® - All rights reserved