CVE-2026-53836 PUBLISHED

OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 12.06.2026 Updated: 12.06.2026

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated operators can bypass execution allowlist checks by using unrecognized encoded-command alias forms to execute arbitrary PowerShell content.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor OpenClaw
Product OpenClaw
Versions Default: unaffected
  • affected from 0 to 2026.5.12 (excl.)
  • Version 2026.5.12 is unaffected

Credits

  • Edward-x (@YLChen-007) reporter

References

Problem Types

  • Incomplete List of Disallowed Inputs CWE