Impact
OpenClaw versions before 2026.5.18 contain an authorization bypass that allows lower‑trust callers to execute or persist actions beyond their intended authorization when the skill command dispatch feature is enabled. The flaw exploits unsafe handling of input paths in the dispatch logic, permitting attackers to circumvent tool policy restrictions and perform unauthorized actions. This is a classic Authorization Bypass Through User‑Controlled Access Chain weakness, compromising the integrity of the system’s access controls and potentially allowing disallowed operations.
Affected Systems
OpenClaw, all releases prior to version 2026.5.18.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity impact. The EPSS score is below 1%, suggesting that the probability of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to invoke the skill command dispatch mechanism while the feature is enabled and reachable, typically through crafted input paths. Unless such access is granted, the attack surface remains limited.
OpenCVE Enrichment