PT-2026-49774 · Openclaw · Openclaw
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.3
Description
A policy enforcement issue exists where Zalo contacts with mutable display metadata can match
allowFrom policy entries by changing their display names. This allows attackers with mutable display names to receive agent responses intended for different Zalo identities when the feature is enabled.Recommendations
Update to version 2026.5.3.
Use stable Zalo identifiers where available and keep friend access restricted.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the affected feature when it is not needed.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw