CVE-2026-53806
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled.
- Affected products
- Openclaw
- Openclaw
- < 2026.5.12
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-367
- NVD status
- Analyzed
- Published
- 2026-06-11
CVE-2026-53806 at NVD
No indexed exploits for CVE-2026-53806 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-53806 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.