Impact
OpenClaw versions 2026.5.12 through 2026.5.25 contain an authorization flaw in the ClickClack allowFrom feature. The flaw allows a caller with lower trust or a specifically configured input path to perform actions beyond the caller’s intended authorization, including executing commands that are not on the allowlist. This results in an unchecked privilege escalation within the application, as the feature does not enforce the proper authentication checks before processing the request, exposing the system to unintended code execution.
Affected Systems
The affected product is OpenClaw, a Node.js‑based tool, with vulnerable releases ranging from 2026.5.12 up to, but not including, 2026.5.26. Any deployment that uses these versions and has the ClickClack allowFrom feature enabled is susceptible to exploitation. Administrators should verify the exact version and whether the feature is active.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity rating, and the EPSS score of less than 1% points to a very small likelihood of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an externally reachable endpoint that has the allowFrom feature enabled; an attacker would need to craft a request that targets this feature to trigger the Bypass. Because the flaw permits command execution outside the allowlist, a successful exploitation could affect the integrity and availability of the affected system, but only for users whose requests reach the vulnerable endpoint.
OpenCVE Enrichment