Impact
OpenClaw 2026.2.12 up to but not including 2026.5.26 contains an authorization bypass that allows a lower‑trust caller to submit blank agent IDs to the hooks allowedAgentIds validation. By sending an empty agent ID, an attacker can circumvent the intended permission checks, enabling them to perform actions that normally require stricter authorization or policy enforcement. This weakness can lead to unauthorized data access, modification, or execution of privileged operations, directly compromising confidentiality, integrity, and availability of the system.
Affected Systems
OpenClaw software from the OpenClaw vendor, specifically the OpenClaw product. Vulnerable releases include version 2026.2.12 up to and excluding 2026.5.26. Any deployment using these releases is affected; newer releases (2026.5.26 and later) contain the fix.
Risk and Exploitability
The CVSS score of 6.0 classifies the issue as medium severity, but the very low EPSS score of less than 1% indicates that exploitation is unlikely to be widespread. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation would occur through the hooks API, where a lower‑trust caller or a misconfigured input path could provide blank agent IDs. An attacker would need network access to the API endpoint or a path that allows the injection of the blank ID; no local privilege escalation is required.
OpenCVE Enrichment