PT-2026-49777 · Unknown+1 · Bluebubbles+1

·

CVE-2026-53860

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.7
Description A sender policy bypass exists in BlueBubbles where participants can match allowlist entries using conversation metadata instead of a stable sender identity. Attackers capable of influencing conversation-level identifiers can receive agent responses intended for configured senders, which may lead to the bypass of access controls.
Recommendations Update to version 2026.5.7. Prefer stable sender identifiers and keep BlueBubbles groups restricted. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the BlueBubbles feature when it is not needed.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53860
GHSA-8HJ2-W4C9-FJFQ
GHSA-8J37-5W68-WJ2G

Affected Products

Bluebubbles
Openclaw