2026 CVE Vulnerabilities

61,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53865HIGH7.2OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-der...
CVE-2026-53864HIGH8.1OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that all...
CVE-2026-53863MEDIUM6.5OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate...
CVE-2026-53862MEDIUM5.4OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to ...
CVE-2026-53861CRITICAL9.8OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined...
CVE-2026-53860MEDIUM5.4OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match ...
CVE-2026-53859MEDIUM6.5OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison...
CVE-2026-53858HIGH7.1OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY c...
CVE-2026-53857HIGH8.6OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata c...
CVE-2026-53856MEDIUM5.7OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores...
CVE-2026-53855HIGH8.1OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict ...
CVE-2026-53854MEDIUM6.5OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t...
CVE-2026-53853HIGH8.3OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to ...
CVE-2026-53852MEDIUM5.4OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticat...
CVE-2026-53851MEDIUM6.3OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent...
CVE-2026-53850MEDIUM6.8OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows aut...
CVE-2026-53849HIGH8.6OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates ...
CVE-2026-53848MEDIUM4.3OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wr...
CVE-2026-53847MEDIUM5.4OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gate...
CVE-2026-53846HIGH7.1OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files...
CVE-2026-53845MEDIUM4.3OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch ...
CVE-2026-53844MEDIUM6.5OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a...
CVE-2026-53843HIGH8.8OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session...
CVE-2026-53842HIGH7.1OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influ...
CVE-2026-53841MEDIUM6.1OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe j...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now