Home

Description

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.write access to modify global configuration without requiring operator.admin privileges. Attackers with operator.write access can exploit insufficient scope validation to apply unauthorized configuration changes beyond the intended write scope.

PUBLISHED Reserved 2026-06-10 | Published 2026-06-16 | Updated 2026-06-16 | Assigner VulnCheck




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Problem types

Incorrect Privilege Assignment

Product status

Default status
unaffected

Any version before 2026.5.6
affected

2026.5.6 (semver)
unaffected

Credits

zsx (@zsxsoft) reporter

KeenSecurityLab coordinator

qclawer tool

References

github.com/...enclaw/security/advisories/GHSA-x629-46cc-7xgw (GitHub Security Advisory (GHSA-x629-46cc-7xgw)) vendor-advisory

www.vulncheck.com/...scalation-via-active-memory-write-scope (VulnCheck Advisory: OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope) third-party-advisory

cve.org (CVE-2026-53847)

nvd.nist.gov (CVE-2026-53847)

Download JSON