HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53828Published Modified CNA VulnCheck

CVE-2026-53828: OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, potentially executing privileged commands from unauthorized users.

Metrics

CVSS v4.0
7.7
Severity
HIGH
Fixed in
2026.5.6
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authorization bypass vulnerability exists in OpenClaw's native command handling prior to version 2026.5.6. The flaw is reachable over the network and requires a low-privilege authenticated account, meaning any registered user can exploit it without needing administrator access. Successful exploitation lets an attacker execute owner-only commands as an unprivileged sender, giving them full read, write, and availability impact on the affected system. A patched-image rebuild at version 2026.5.6 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle OpenClaw.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 7.7 HIGH and weighting it against each environment's compliance policy to determine urgency. Triage alerts are routable to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.6 becomes available on HarborGuard for any environment where an affected version is detected. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The vulnerable native command handler is exposed over the network, so an attacker must be able to reach the service remotely to exploit it.

  • AuthenticationRequired

    A low-privilege authenticated account is sufficient; no administrator or elevated role is needed to trigger the bypass.

  • Victim interactionNot required

    No victim action such as clicking a link or opening a file is needed; the attacker initiates the exploit entirely on their own.

  • Attack complexityDetail

    Base exploit complexity is low and condition-free, though the attack requires a specific precondition (AT:P) such as a particular system state or configuration being present.

Blast Radius

  • A successful attacker executes owner-only privileged commands as an unprivileged sender, bypassing all configured access controls.
  • The attacker gains full read access to confidential data stored or processed by the OpenClaw instance, including any secrets or session material it handles.
  • The attacker can modify or delete persisted data and configuration managed by OpenClaw.
  • The attacker can disrupt or crash the OpenClaw service, causing a loss of availability for any workloads depending on it.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-53828 is active across connected registries and pipelines, with images matched against the affected OpenClaw version range (below 2026.5.6) within minutes of CVE publication. A patched-image rebuild targeting OpenClaw 2026.5.6 is available for any environment where an affected image is identified. For customers who opt into auto-remediation, HarborGuard can rebuild the image, execute regression tests, and open a pull request against affected workloads; for high-severity issues, median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy permits, the rebuilt image is promoted automatically through the customer's defined promotion gates. Customers who manage their own remediation workflow will find the affected images flagged with full CVSS detail and fix-version guidance in their HarborGuard dashboard.

See how HarborGuard automates this

Fix available

2026.5.6
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.6 (from 0)
    Fixed in 2026.5.6
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N