PT-2026-49777 · Unknown+1 · Bluebubbles+1
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.7
Description
A sender policy bypass exists in BlueBubbles where participants can match allowlist entries using conversation metadata instead of a stable sender identity. Attackers capable of influencing conversation-level identifiers can receive agent responses intended for configured senders, which may lead to the bypass of access controls.
Recommendations
Update to version 2026.5.7.
Prefer stable sender identifiers and keep BlueBubbles groups restricted.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the BlueBubbles feature when it is not needed.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bluebubbles
Openclaw