Junglewise Threat Intelligence

CVE-2026-53857: OpenClaw policy enforcement bypass in Zalo allowFrom policy

CVE-2026-53857 · Severity: high · CVSS 8.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway for managing Zalo communications, contains a flaw in how it identifies users. An attacker can change their display name to match a trusted user's name, potentially tricking the system into sending them messages or data intended for someone else. This could lead to unauthorized access to private communications or sensitive information.

Technical details

A vulnerability in OpenClaw's Zalo 'allowFrom' policy implementation allows for authentication bypass via spoofing (CWE-290). The root cause is the system's reliance on mutable display metadata rather than stable, unique identifiers when evaluating access policies. An attacker with a Zalo account can modify their display name to match a name listed in a policy entry, potentially receiving agent responses or data intended for a different identity. This requires the 'allowFrom' feature to be enabled and reachable. The issue is addressed in version 2026.5.3 by prioritizing stable identifiers.

Affected products

  • openclaw openclaw <= 2026.5.2

Timeline

  • 2026-05-28: disclosed: Initial disclosure by reporter
  • 2026-06-18: advisory: GitHub Advisory published
  • 2026-05-28: patched: Version 2026.5.3 released

References

Related threats