Junglewise Threat Intelligence

CVE-2026-53815: OpenClaw authorization bypass in message read actions

CVE-2026-53815 · Severity: medium · CVSS 6.5 · Published 2026-06-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a communication gateway tool, contains a flaw where certain message-reading actions fail to verify if a user is authorized to access specific channels. This allows users with low-level access to bypass security restrictions and read private messages from channels they should not be able to see. An exploit could lead to the exposure of sensitive internal communications and data.

Technical details

A missing authorization vulnerability (CWE-862) exists in OpenClaw's message read actions. The root cause is that certain read paths do not enforce the same channel allowlist checks used during normal message delivery. An authenticated attacker with 'lower-trust' caller privileges can exploit this over the network to request and receive messages from restricted channels. This results in the exposure of sensitive information (CWE-200). The issue is patched in version 2026.5.19.

Affected products

  • openclaw openclaw <= 2026.5.19-beta.2

Timeline

  • 2026-05-28: disclosed: Vulnerability published to openclaw/openclaw repository
  • 2026-06-11: advisory: NVD publication date
  • 2026-07-02: advisory: GitHub Advisory Database publication date

References

Related threats