CVE-2026-45006Patch(openclaw / openclaw)

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete denylist protection. Attackers can persist malicious config modifications affecting command execution, network behavior, credentials, and operator policies that survive restart.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-12)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-11: 1Mentions · 2026-05-12: 2Patch / Workaround · 2026-05-12: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 105-1105-12
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-122
Patch2
Full discourse3 posts
  • klawlikula@klawlikula
    Patch

    Two high-severity CVEs to patch now: • CVE-2026-45223 — Crabbox <0.9.0 • CVE-2026-45006 — OpenClaw <2026.4.23 Both are CVSS 8.8, with no active exploitation or PoC reported yet.

    Post summary

    The post highlights two high‑severity CVEs (CVE-2026-45223 and CVE-2026-45006), urges immediate patching of the affected versions, and notes no active exploitation or PoC.

    2001059
    3 followersView on X
  • klawlikula@klawlikula
    Patch

    CVE-2026-45006 (OpenClaw): someone may reach gateway config areas they should not be able to access. Fix: upgrade to 2026.4.23+.

    Post summary

    The entry reports CVE‑2026‑45006 in OpenClaw, describing an access‑control flaw that allows unauthorized gateway config access, and advises upgrading to 2026.4.23+.

    0000022
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45006 OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised mod… https://www.cve.org/CVERecord?id=CVE-2026-45006

    Post summary

    This brief notice announces CVE-2026-45006, an improper access control vulnerability in OpenClaw's gateway tool (config.apply/patch) before version 2026.4.23, with no additional details on PoC, exploits, patches, or active attacks.

    0000089
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more