CVE-2026-53811 PUBLISHED

OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFrom

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 11.06.2026 Updated: 11.06.2026

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor OpenClaw
Product OpenClaw
Versions Default: unaffected
  • affected from 0 to 2026.5.7 (excl.)
  • Version 2026.5.7 is unaffected

Credits

  • Philip (@PhilipPhil) reporter

References

Problem Types

  • Authentication Bypass by Spoofing CWE