Beveiligingsadvies

CVE-2026-53808

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-11 20:06:14
Laatst bijgewerkt 2026-06-23 16:16:49
Toegewezen door VulnCheck
CVSS-score 6.5
Status PUBLISHED

Beschrijving

OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before the expected approval step, potentially modifying configurations without proper authorization.