Impact
OpenClaw versions prior to 2026.5.19 contain an authorization bypass flaw in the browser act route that does not correctly honor current‑tab URL checks. An attacker who can access the application with a lower‑trust credential or can craft a request to a configured input path can trigger actions that normally require greater authorization or policy verification, potentially allowing unauthorized data access or command execution.
Affected Systems
The vulnerability affects the OpenClaw application. All installations using OpenClaw version 2026.3.28 or earlier are susceptible. Versions 2026.5.19 and later include the fixed authorization check.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity and the EPSS score of less than 1 % shows that exploitation is not currently widespread. The flaw is not listed in the CISA KEV catalog. Attackers would likely use a browser‑based request to the vulnerable route, requiring network access to the application and either a lower‑trust login or the ability to manipulate input paths. Successful exploitation would allow privileged operations without meeting normal authorization checks.
OpenCVE Enrichment