Impact
OpenClaw versions prior to 2026.6.5 contain a logic flaw in which user authorization checks on admin‑scoped tools are insufficient. The vulnerability is a policy‑evasion bug that allows callers with lower trust levels to access features normally restricted to administrators, resulting in the ability to perform operations that require higher privileges. This weakness is captured by CWE‑862, Unauthorized Access: Privilege Escalation.
Affected Systems
The affected product is OpenClaw, as listed by the Vendor–Product naming in the CNA. All releases of OpenClaw before the 2026.6.5 build are vulnerable; subsequent releases are presumed fixed.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑severity threat, while the EPSS score of less than 1% suggests exploit attempts are rare but possible. The vulnerability is not cataloged in CISA’s KEV list. Attackers can exploit the weakness by invoking administrative endpoints that lack proper policy enforcement; this can be performed by any client with lower trust rather than requiring full authentication. The description does not explicitly state the attack vector, so it is inferred that the attack may be conducted remotely or locally depending on network exposure. The combination of high severity and the likelihood of exploitation places the risk at a level that warrants urgent remediation.
OpenCVE Enrichment