OpenClaw
- >= 2026.6.1, < 2026.6.9
A privilege escalation vulnerability has been identified in OpenClaw versions 2026.6.1 prior to 2026.6.9. This vulnerability exists within isolated cron jobs, allowing lower-trust callers to regain access to denied execution tools. By exploiting misconfigured input paths in the affected cron feature, attackers can execute or persist actions beyond their authorized permissions.
Exploitation of this vulnerability could lead to unauthorized execution or persistence of actions, bypassing the intended authorization limits of the user or process.
Users are advised to upgrade to OpenClaw version 2026.6.9 or later. Before upgrading, it is recommended to restrict the affected cron feature to trusted operators or disable it if not needed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.