CVE-2026-53844

EUVD-2026-37146
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
openclawopenclaw
𝑥
< 2026.4.29
openclawopenclaw
2026.4.29:beta1
openclawopenclaw
2026.4.29:beta2
openclawopenclaw
2026.4.29:beta3
openclawopenclaw
2026.4.29:beta4
𝑥
= Vulnerable software versions