CVE-2026-53829
Medium
Elevated severity or exploit probability.
CVSS base
8.0
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.2%
14.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-451
Published 2026-06-12 · modified 2026-07-23
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | R | Required |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | H | High |
| Availability | H | High |
Timeline
- 2026-06-12 — Published (NVD)
- 2026-07-23 — Last modified (NVD)
Description
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.