Junglewise Threat Intelligence

CVE-2026-53833: OpenClaw QQBot authorization bypass in streaming command

CVE-2026-53833 · Severity: high · CVSS 7.7 · Published 2026-06-12

Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing bot integrations, contains a security flaw in its QQBot streaming command. This vulnerability allows users who can send commands to the bot to change its configuration settings without proper authorization. An attacker could exploit this to bypass administrative policies and modify how the bot handles data streams, potentially leading to unauthorized access or service disruption.

Technical details

An authorization bypass vulnerability exists in OpenClaw's QQBot streaming command due to improper enforcement of 'allowFrom' restrictions. In affected versions prior to 2026.4.29, the system fails to require an explicit, non-wildcard allowlist entry for configuration mutation commands. An authenticated sender reaching the affected command path can modify the QQBot streaming configuration outside of the intended administrative policy. The vulnerability is classified as CWE-290 (Authentication Bypass by Spoofing) and can be mitigated by disabling the command or restricting it to trusted senders until the patch is applied.

Affected products

  • OpenClaw OpenClaw QQBot < 2026.4.29

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: NVD publication date

References