OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session. | |
| Title | OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-16T18:39:20.445Z
Reserved: 2026-06-10T21:19:32.652Z
Link: CVE-2026-53844
No data.
Status : Received
Published: 2026-06-16T19:17:01.390
Modified: 2026-06-16T19:17:01.390
Link: CVE-2026-53844
No data.
OpenCVE Enrichment
Updated: 2026-06-16T19:30:16Z