Impact
OpenClaw versions before 2026.6.9 contain an authorization bypass in the message mutation handling path that allows callers with lower trust levels to perform actions that normally require higher privileges. The flaw arises from missing or inadequate authorization checks during mutation processing, as identified by CWE-862 and CWE-863. Attackers can trigger privileged operations by sending crafted mutation requests, potentially compromising data confidentiality, integrity, and availability of the application.
Affected Systems
The affected product is OpenClaw, specifically any Node.js deployment running OpenClaw 2026.6.6 through 2026.6.8. Users who have not upgraded to version 2026.6.9 or later are exposed to this vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS value of less than 1% suggests a low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves accessing the message mutation feature via misconfigured input paths, allowing an attacker to inject authorization‑bypassing requests when the feature is enabled and reachable.
OpenCVE Enrichment