CVE-2026-53866
OpenClaw OpenClaw, openclaw
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.
- CVSS
- 7.6
- EPSS
- 0.27% 19.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.17