CVE-2026-53850
Description
OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels.
Summary dbcve.org
OpenClaw before version 2026.4.25 has a control scope enforcement bypass in the focus command. The vulnerability allows authenticated users to execute the focus command without proper authorization checks, enabling them to change focus state outside their intended caller authority scope. This is an access control bypass that could allow unauthorized operations depending on gateway configuration and trust levels.
Mitigation
Upgrade to OpenClaw version 2026.4.25 or later which contains the fix. Additionally, review and enforce proper authorization checks on the focus command to ensure callers can only change focus states within their authorized scope.