PT-2026-49768 · Openclaw · Openclaw

Edward-X

·

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53851

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-53851

Affected Products

Openclaw