OpenClaw 2026.6.6 Stable Release Brings Major Security Hardening
OpenClaw has shipped 2026.6.6 stable, a release focused almost entirely on tightening security boundaries across the board. The release was first seeded as beta on June 10th, promoted through two beta releases, and is now the recommended stable build.
Whatβs Hardened
The release tightens security in a long list of areas:
- Transcripts β sandbox binds and host environment inheritance now more strictly enforced
- MCP stdio β native search policy and elevated sender checks strengthened
- Codex HTTP access β tighter controls on outbound HTTP from agent sessions
- Deleted-agent ACP bypasses β closed a path where removed agents could still execute via ACP
- Loopback tools β loopback-only tool access now properly gated
- Discord moderation and Teams group actions β platform-specific boundary fixes
- Exec approvals β now fail closed on policy violations, meaning denied requests are rejected rather than silently allowed to proceed
The security team noted this is the most comprehensive single-pass hardening in the projectβs recent history, touching nearly every boundary layer in the runtime.
Upgrade Recommendation
Users on any earlier version β especially those running multi-user or networked setups β are encouraged to upgrade promptly. The fail-closed exec behavior change may require users to re-approve previously allowed commands that were borderline on risk policy.