← العودة للجدول
CVE-2026-53814
CVE-2026-53814 — OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where ho
📅 2026-06-11
🟠 High 🔥 No NVD Exploit Exploit CVSS 8.3

📋 الوصف الكامل

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-53814

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-53814 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←