HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53866Published Modified CNA VulnCheck

CVE-2026-53866: OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.

Metrics

CVSS v4.0
7.6
Severity
HIGH
Fixed in
2026.5.12
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An allowlist bypass vulnerability exists in OpenClaw's shell inline-command parser, affecting all versions before 2026.5.12. The flaw is reachable over the network by any authenticated operator-level account, requiring no interaction from a victim. Successful exploitation lets an attacker execute arbitrary shell commands that should have been blocked by the allowlist, bypassing the approval controls meant to gate privileged operations. A patched-image rebuild at version 2026.5.12 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-53866 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of publication. Coverage extends to custom-built images that bundle OpenClaw, not just upstream base images.

Available
Triage

HarborGuard is capable of scoring this CVE at its published CVSS v4.0 rating of 7.6 (HIGH) and weighting it against each environment's compliance policy to surface the right priority signal. Routing to the appropriate team inbox within a customer organization is handled automatically based on policy configuration.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.12 becomes available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard is capable of performing the rebuild, running a regression test suite, and opening a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The vulnerable parser endpoint is exposed over the network, so an attacker must be able to reach the OpenClaw service remotely.

  • AuthenticationRequired

    A low-privilege operator-level account is sufficient; no administrative credentials are needed to trigger the bypass.

  • Victim interactionNot required

    The attacker can exploit this flaw entirely on their own without requiring any action from another user.

  • Attack complexityDetail

    While the exploit path itself is reliable and condition-free, a specific attack target requirement (AT:P) means certain environmental or configuration preconditions must align for the bypass to succeed.

Blast Radius

  • Reads files, environment variables, or secrets accessible to the OpenClaw process by executing unapproved shell commands.
  • Writes to or modifies files, configuration, or state that the process has access to, bypassing the approval controls intended to prevent such changes.
  • The service itself is not crashed by this exploit (availability impact is none), so the attacker can operate persistently without triggering an outage-based alert.

How HarborGuard Handles This

Available on HarborGuard: detection of CVE-2026-53866 is active for all images containing OpenClaw versions prior to 2026.5.12, with results surfaced at a CVSS v4.0 HIGH (7.6) priority. Where compliance policy permits, HarborGuard can trigger a rebuild against the fixed version 2026.5.12, run regression tests, and open a PR against affected workloads. For environments with auto-remediation enabled, the median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes. For teams that need to gate on a manual review before merging, the rebuilt image is staged and the PR is held open pending approval. No specific customer environment is acted on without the configuration settings that customer has defined.

See how HarborGuard automates this

Fix available

2026.5.12
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.12 (from 0)
    Fixed in 2026.5.12
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N