HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53836Published Modified CNA VulnCheck

CVE-2026-53836: OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated operators can bypass execution allowlist checks by using unrecognized encoded-command alias forms to execute arbitrary PowerShell content.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
2026.5.12
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An allowlist bypass vulnerability exists in OpenClaw before version 2026.5.12, affecting its PowerShell encoded-command handling. The flaw is reachable over the network by any authenticated operator (a low-privilege account is sufficient), with no victim interaction required. Successful exploitation lets an attacker run arbitrary PowerShell commands that the allowlist was meant to block, enabling full read, write, and denial-of-service impact on the affected system. A patched-image rebuild at version 2026.5.12 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection for CVE-2026-53836 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of publication. Coverage extends to custom-built images that bundle OpenClaw, not only upstream base images.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.7 (HIGH) and weighting that score against each customer environment's compliance policy to determine urgency. Triage routing to the appropriate team inbox within each customer org is available automatically based on those policy rules.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.12 is available on HarborGuard for any environment found to be running an affected version. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the OpenClaw service over the network; local or physical access is not needed.

  • AuthenticationRequired

    A low-privilege operator account is sufficient; no administrative or elevated credentials are required.

  • Victim interactionNot required

    No user interaction is needed; the attacker can trigger the bypass entirely on their own.

  • Attack complexityDetail

    Exploitation is reliable and condition-free; no race conditions or specific memory layout assumptions are required.

Blast Radius

  • The attacker reads any data accessible to the PowerShell execution context, including secrets, credentials, and configuration files on the host.
  • The attacker writes or modifies files and system state, overwriting configuration, dropping payloads, or altering persisted data.
  • The attacker can crash or exhaust resources on the affected service, causing a denial of service for dependent workloads.
  • All three impacts are achievable in a single session because the allowlist bypass grants unrestricted PowerShell execution.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-53836 is active for all scanned images, including custom images that vendor or embed OpenClaw. For environments running an affected version (any release before 2026.5.12), a rebuilt image at the fixed version is available immediately. For customers with auto-remediation enabled, HarborGuard can rebuild the image, execute regression tests, and open a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in those environments. For customers who manage remediation manually, HarborGuard surfaces the finding with its CVSS 8.7 score and fix-version detail so that upgrading to 2026.5.12 can be prioritized and tracked through the standard compliance workflow.

See how HarborGuard automates this

Fix available

2026.5.12
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.12 (from 0)
    Fixed in 2026.5.12
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N