CVE-2026-53811

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

12 Jun 2026, 19:32

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-7hxm-f538-3xp6 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-7hxm-f538-3xp6 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-display-names-in-matrix-allowfrom - () https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-display-names-in-matrix-allowfrom - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw
Openclaw openclaw

11 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 21:16

Updated : 2026-06-17 10:58


NVD link : CVE-2026-53811

Mitre link : CVE-2026-53811

CVE.ORG link : CVE-2026-53811


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-290

Authentication Bypass by Spoofing