Impact
OpenClaw versions prior to 2026.6.5 contain an authorization bypass in the ClickClack agent‑mode dispatch feature. The bug allows the tool to ignore the toolsAllow policy check, so callers with lower trust or attacks that supply a configured input path can invoke actions that normally require stronger authorization. The resulting compromise could allow an attacker to read, modify, or delete data and potentially disrupt application functionality.
Affected Systems
The affected product is OpenClaw OpenClaw released as software for Node.js environments. Vulnerable releases include 2026.5.10-beta.1 and all earlier versions up to but not including 2026.6.5. Users running these versions should verify their deployment environment and confirm whether the ClickClack agent‑mode dispatch feature is enabled.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while the EPSS score of less than 1 percent shows that currently the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation. If the affected feature is reachable—either through a publicly exposed API or a local service—an attacker who can manipulate input paths or impersonate a lower‑trust caller can trigger the bypass. The attack vector is inferred to be local or remote access to the dispatch endpoint, and requires the feature to be enabled and reachable.
OpenCVE Enrichment