CVE-2026-53807

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

12 Jun 2026, 19:33

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-w5ww-7chg-mxcq - () https://github.com/openclaw/openclaw/security/advisories/GHSA-w5ww-7chg-mxcq - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-telegram-interactive-callbacks-via-commands-allowfrom - () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-telegram-interactive-callbacks-via-commands-allowfrom - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw
Openclaw openclaw

11 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 21:16

Updated : 2026-06-12 19:33


NVD link : CVE-2026-53807

Mitre link : CVE-2026-53807

CVE.ORG link : CVE-2026-53807


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-863

Incorrect Authorization