PT-2026-48745 · Openclaw · Openclaw

Samchodev

·

Published

2026-06-11

·

Updated

2026-06-11

·

CVE-2026-53815

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensitive channel messages.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-53815

Affected Products

Openclaw