HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53832Published Modified CNA VulnCheck

CVE-2026-53832: OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.

Metrics

CVSS v4.0
7.4
Severity
HIGH
Fixed in
2026.5.18
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an identity header forgery vulnerability in OpenClaw versions before 2026.5.18. An attacker with local access to the proxy-facing Gateway port can supply crafted HTTP headers that impersonate a trusted proxy, bypassing identity validation without any authentication. Successful exploitation lets the attacker assume operator identity and escalate privileges within the application. A patched-image rebuild at version 2026.5.18 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-53832 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of its publication on 2026-06-12, including custom-built images that bundle OpenClaw. Coverage extends to both registry scans and in-pipeline image checks at build time.

Available
Triage

HarborGuard is capable of scoring this CVE at 7.4 HIGH (CVSS v4.0) and weighting it against each environment's compliance policy to determine urgency. Triage routing is available to direct findings to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.18 becomes available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityNot required

    The attacker needs an existing shell or process on the host; the vulnerable Gateway port is local to the machine, so no over-the-network access path is required.

  • AuthenticationNot required

    No credentials or account are required; the attacker only needs local access to the Gateway port to begin sending forged headers.

  • Victim interactionNot required

    The exploit is self-contained and does not require any action from another user or operator to succeed.

  • Attack complexityDetail

    The exploit is reliable and condition-free in terms of logic, though the CVSS AT:P token notes that a specific precondition (access to the proxy-facing Gateway port) must already be in place for the attack to work.

Blast Radius

  • Reads identity context and session data belonging to operator-level accounts, including any credentials or tokens stored under that identity.
  • Writes or modifies application state as an operator, including configuration changes and privilege assignments for other users.
  • Allows the attacker to impersonate an operator account persistently for the duration of their local access, enabling further lateral movement within the application.

How HarborGuard Handles This

Available on HarborGuard: scanning for CVE-2026-53832 runs against all customer images at ingestion time, with results available immediately after the CVE was published. For environments running OpenClaw below 2026.5.18, a patched rebuild at the fix version is available. For customers who opt into auto-remediation, HarborGuard can rebuild the image, run regression tests, and open a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, HarborGuard surfaces the finding with CVSS context and fix version detail so engineers can act manually. As a compensating control until patching is complete, network policy isolation restricting local access to the Gateway port is recommended to limit the pool of processes that can reach the vulnerable endpoint.

See how HarborGuard automates this

Fix available

2026.5.18
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.18 (from 0)
    Fixed in 2026.5.18
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N