CVE-2026-53854
Description
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope, potentially bypassing access controls.
Summary dbcve.org
OpenClaw before version 2026.4.25 has a privilege escalation vulnerability in its internal and webchat command authentication system. The flaw allows attackers to inherit wildcard 'ownerAllowFrom' state across channel boundaries, enabling execution of owner-privileged commands outside the intended channel scope and bypassing access controls.
Mitigation
Upgrade to OpenClaw version 2026.4.25 or later to patch the authentication bypass. Additionally, audit existing channel permissions and monitor for unauthorized owner-level command execution across channels.