PT-2026-49041 · Openclaw+1 · Openclaw+1

·

CVE-2026-53837

·

Published

2026-06-12

·

Updated

2026-07-02

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.6
Description Improper access control in Mattermost event handlers occurs due to a failure to validate channel type metadata. This allows attackers to bypass intended Direct Message (DM) policy decisions by sending crafted Mattermost events that lack channel type information to process restricted content.
Recommendations Update to version 2026.5.6.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53837
GHSA-GP79-M99V-GJMH

Affected Products

Mattermost
Openclaw