Impact
OpenClaw versions earlier than 2026.6.5 can forward HTTP Authorization headers when the MCP SSE redirect feature is enabled. As a result, a lower‑trust caller or misconfigured input path can cause the downstream service to process requests under an unintended, higher‑privilege identity. The flaw is a credential‑protection weakness that permits privilege escalation, identified as CWE‑522.
Affected Systems
The affected product is OpenClaw software running in a Node.js environment. Hosts running any version prior to 2026.6.5 with the MCP SSE redirect feature enabled and exposed to external callers are vulnerable. The vulnerability becomes active when the SSE redirect endpoint is reachable and the forwarding of header information is configured.
Risk and Exploitability
The CVSS base score of 6 indicates moderate impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation today. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be able to trigger the SSE redirect path from a lower‑trust endpoint and supply a request that contains an Authorization header. Once forwarded, the downstream service acts with the elevated credentials, enabling the attacker to perform privileged actions. Because the feature must be enabled and accessible, the attack surface is relatively narrow, but in environments where the redirect is exposed to untrusted clients the risk of unauthorized privilege escalation is real.
OpenCVE Enrichment