CVE-2026-53823

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

16 Jun 2026, 02:52

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-c29c-2q9c-pc86 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-c29c-2q9c-pc86 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-slack-display-names-in-allowfrom - () https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-slack-display-names-in-allowfrom - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

12 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 22:16

Updated : 2026-06-17 10:58


NVD link : CVE-2026-53823

Mitre link : CVE-2026-53823

CVE.ORG link : CVE-2026-53823


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-290

Authentication Bypass by Spoofing