CVE-2026-53832
OpenClaw OpenClaw, openclaw
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.
- CVSS
- 7.4
- EPSS
- 0.10% 1.10% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.13