CVE-2026-53807 PUBLISHED

OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 11.06.2026 Updated: 12.06.2026

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor OpenClaw
Product OpenClaw
Versions Default: unaffected
  • affected from 0 to 2026.5.6 (excl.)
  • Version 2026.5.6 is unaffected

Credits

  • zsx (@zsxsoft) reporter
  • KeenSecurityLab coordinator
  • qclawer tool

References

Problem Types

  • Incorrect Authorization CWE