OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | 0 |
Updated severity from NONE to CRITICAL and clarified affected versions as all versions up to 2026.6.4
Initial creation