OpenClaw Privilege Escalation Vulnerability in Cron Jobs

Vulnerability

A privilege escalation vulnerability has been identified in OpenClaw versions 2026.6.1 prior to 2026.6.9. This vulnerability exists within isolated cron jobs, allowing lower-trust callers to regain access to denied execution tools. By exploiting misconfigured input paths in the affected cron feature, attackers can execute or persist actions beyond their authorized permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized execution or persistence of actions, bypassing the intended authorization limits of the user or process.

Remediation

Users are advised to upgrade to OpenClaw version 2026.6.9 or later. Before upgrading, it is recommended to restrict the affected cron feature to trusted operators or disable it if not needed.

Added: Jul 17, 2026, 3:37 AM
Updated: Jul 17, 2026, 3:37 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.