Impact
OpenClaw versions prior to 2026.6.9 contain an authorization bypass flaw in the flock wrapper that allows callers with lower trust levels to execute or persist operations that exceed their intended permissions. The vulnerability arises when attackers supply specific input paths that the application processes, enabling them to bypass durable execution approval binding and carry out unauthorized actions. The weakness is a form of improper authorization control, classified as CWE-706 and CWE-863. The impact is the ability for an attacker to elevate privileges within the OpenClaw system, potentially gaining control over protected resources or data.
Affected Systems
The affected product is OpenClaw, a Node.js based application. All releases before 2026.6.9 are vulnerable, as noted in the CNA vendor product list. No specific distribution or configuration details beyond the stated feature being enabled are provided.
Risk and Exploitability
The CVSS score of 8.7 marks this issue as high severity, and while the EPSS score is about 0.3%, the lack of KEV listing suggests no widespread exploitation so far. Attackers are likely to exploit the flaw by providing crafted input paths while the flock wrapper feature is enabled, and based on the description, it is inferred that exploitation could occur in both local and remote contexts depending on how input is supplied. The risk is significant given the ability to bypass authorization altogether.
OpenCVE Enrichment