PT-2026-49768 · Openclaw · Openclaw

·

CVE-2026-53851

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.12
Description A notification bypass allows Slack reaction events to enter the agent pipeline even when reaction notifications are disabled. This can trigger unintended agent processing for reaction events, potentially leading to the unauthorized processing of lower-trust input. This issue occurs when the affected feature is enabled and reachable.
Recommendations Update to version 2026.5.12. Disable or restrict Slack reaction event subscriptions if this path is not required. Disable the affected feature when it is not needed. Keep channel and tool allowlists narrow and avoid sharing one Gateway between mutually untrusted users.

Exploit

Fix

Improper Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53851
GHSA-C8W7-9W9H-X69Q
GHSA-FCVX-5CXC-V5P8

Affected Products

Openclaw