Impact
The vulnerability arises from improper enforcement of access control in the MCP loopback feature, allowing callers with lower trust levels to run tools reserved for the system owner. Attackers can trigger these privileged operations by supplying specific input paths that the system interprets as authorized. The result is an authorization bypass that can lead to unauthorized code execution, persistence, or data tampering, as the exploited weakness is classified as CWE-732.
Affected Systems
Affected are installations of OpenClaw version 2026.5.20 up to but not including 2026.6.6. These releases run on a Node.js runtime and contain the MCP loopback component that can be accessed by external callers. All users of these versions are at risk if the loopback is enabled, regardless of the individual host environment.
Risk and Exploitability
The severity is high with a CVSS score of 8.7, and the EPSS score of <1% indicates low but nonzero exploitation probability. The vulnerability is not in the CISA KEV list, indicating no confirmed exploitation yet. Based on the description, the likely attack vector involves the MCP loopback interface—an entry point reachable from low‑trust callers—to override authentication checks and invoke owner‑only tools. Such bypass permits execution of privileged code, potential persistence, and modification of protected data.
OpenCVE Enrichment