Impact
The vulnerability is an authorization bypass in OpenClaw’s native web search. Lower‑trust callers can interact with the search interface, and the software fails to enforce the stronger policy checks that normally guard the operations invoked through that path. As a result, an attacker can perform actions that should be restricted to higher‑privileged users, such as accessing protected resources or executing privileged commands. The weakness corresponds to CWE-863, a flaw in privilege‑based access control.
Affected Systems
OpenClaw OpenClaw versions prior6.6 are affected. The product runs on a Node.js environment; the specific affected releases are those from 2026.5.28 up to and including 2026.6.5.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is <1%, implying a very low exploitation probability in the current environment. Since the vulnerability is not listed in CISA KEV, there is little evidence of active exploitation. The likely attack vector is the web search feature over HTTP/HTTPS, where an attacker crafts requests exploiting misconfigured input paths to bypass authorization logic. The vulnerability requires the ability to use the web search interface; it does not require local privilege elevation or remote code execution, but allows illicit privilege escalation within the application.
OpenCVE Enrichment