Junglewise Threat Intelligence

CVE-2026-53811: OpenClaw privilege escalation in Matrix allowFrom feature

CVE-2026-53811 · Severity: high · CVSS 8.8 · Published 2026-06-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway tool for Matrix communications, contains a flaw where it identifies users based on their display names rather than permanent IDs. Because display names can be changed by anyone, an attacker could change their name to match a trusted user and gain unauthorized access to tools or data. This could lead to a complete takeover of the gateway's functions by an unauthorized party.

Technical details

OpenClaw versions up to 2026.5.6 are vulnerable to an authentication bypass (CWE-290) in the Matrix 'allowFrom' policy feature. The root cause is the application's reliance on mutable display name metadata for identity verification instead of stable Matrix user IDs. An authenticated Matrix user with the ability to change their own display name can spoof a trusted identity defined in the gateway's allowlist. If the 'allowFrom' feature is enabled, this allows the attacker to gain agent access or execute commands intended for a different user. The vulnerability is patched in version 2026.5.7.

Affected products

  • openclaw openclaw <= 2026.5.6

Timeline

  • 2026-05-28: disclosed
  • 2026-06-11: advisory: NVD publication date
  • 2026-07-02: advisory: GitHub Advisory reviewed

References

Related threats