OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-7hxm-f538-3xp6 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-display-names-in-matrix-allowfrom | Third Party Advisory |
Configurations
History
12 Jun 2026, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-7hxm-f538-3xp6 - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-display-names-in-matrix-allowfrom - Third Party Advisory | |
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw
Openclaw openclaw |
11 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 21:16
Updated : 2026-06-17 10:58
NVD link : CVE-2026-53811
Mitre link : CVE-2026-53811
CVE.ORG link : CVE-2026-53811
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-290
Authentication Bypass by Spoofing
