2026 CVE Vulnerabilities
61,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53865 | HIGH | 7.2 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-der... |
| CVE-2026-53864 | HIGH | 8.1 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that all... |
| CVE-2026-53863 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate... |
| CVE-2026-53862 | MEDIUM | 5.4 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to ... |
| CVE-2026-53861 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined... |
| CVE-2026-53860 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match ... |
| CVE-2026-53859 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison... |
| CVE-2026-53858 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY c... |
| CVE-2026-53857 | HIGH | 8.6 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata c... |
| CVE-2026-53856 | MEDIUM | 5.7 | 0.1% | Jun 16, 2026 | OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores... |
| CVE-2026-53855 | HIGH | 8.1 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict ... |
| CVE-2026-53854 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t... |
| CVE-2026-53853 | HIGH | 8.3 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to ... |
| CVE-2026-53852 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticat... |
| CVE-2026-53851 | MEDIUM | 6.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent... |
| CVE-2026-53850 | MEDIUM | 6.8 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows aut... |
| CVE-2026-53849 | HIGH | 8.6 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates ... |
| CVE-2026-53848 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wr... |
| CVE-2026-53847 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gate... |
| CVE-2026-53846 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files... |
| CVE-2026-53845 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch ... |
| CVE-2026-53844 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a... |
| CVE-2026-53843 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session... |
| CVE-2026-53842 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influ... |
| CVE-2026-53841 | MEDIUM | 6.1 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe j... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now