Metrics
Affected Vendors & Products
Tue, 16 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels. | |
| Title | OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-16T18:38:31.964Z
Reserved: 2026-06-10T21:21:12.125Z
Link: CVE-2026-53850
Updated: 2026-06-16T18:38:27.632Z
Status : Awaiting Analysis
Published: 2026-06-16T19:17:02.183
Modified: 2026-06-16T20:42:46.200
Link: CVE-2026-53850
No data.
OpenCVE Enrichment
Updated: 2026-06-16T21:00:12Z