PT-2026-49774 · Openclaw · Openclaw

·

CVE-2026-53857

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.3
Description A policy enforcement issue exists where Zalo contacts with mutable display metadata can match allowFrom policy entries by changing their display names. This allows attackers with mutable display names to receive agent responses intended for different Zalo identities when the feature is enabled.
Recommendations Update to version 2026.5.3. Use stable Zalo identifiers where available and keep friend access restricted. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the affected feature when it is not needed.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53857
GHSA-8C59-HR4W-QG69
GHSA-W7M7-3XCF-MP48

Affected Products

Openclaw