CVE-2026-53811Disclosure(openclaw / openclaw)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-16: 1Technical Details · 2026-06-16: 106-16
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-53811 just dropped. High severity — worth your attention today. OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allo... The best defense is the one you set up before you needed it.

    Post summary

    CVE-2026-53811 is a newly disclosed high‑severity privilege escalation issue affecting OpenClaw versions earlier than 2026.5.7. The post offers no PoC, exploit code, or patch information.

    0000041
    337 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more