CVE-2026-53837
- EPSS 0.19%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 16.06.2026 00:21:33
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events missing chann...
CVE-2026-53838
- EPSS 0.22%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 16.06.2026 02:54:55
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than in...
CVE-2026-53839
- EPSS 0.27%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 16.06.2026 02:54:28
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to se...
CVE-2026-53827
- EPSS 0.25%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 02:55:53
OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can inte...
CVE-2026-53828
- EPSS 0.27%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 02:55:43
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to by...
- EPSS 0.23%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 02:55:31
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute ...
CVE-2026-53830
- EPSS 0.21%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 02:55:05
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook event...
CVE-2026-53831
- EPSS 0.19%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 00:45:31
OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in...
CVE-2026-53832
- EPSS 0.1%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 00:37:37
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assu...
CVE-2026-53833
- EPSS 0.17%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 16.06.2026 00:34:44
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configurat...