Executive brief
OpenClaw, a tool used for managing Discord-based agent access, contains a flaw in how it identifies authorized users. An attacker can gain unauthorized access to administrative tools or sensitive data by simply changing their Discord display name to match an authorized user's name. This could lead to a full takeover of the agent's capabilities and exposure of internal operations.
Technical details
A privilege escalation vulnerability exists in OpenClaw's 'allowFrom' feature due to improper identity validation (CWE-290). The system matches Discord accounts against access policies using mutable display names or global names rather than immutable, unique Discord snowflakes (User IDs). An attacker with a valid Discord account can change their display name to impersonate a trusted identity defined in the configuration. If the affected feature is reachable, the attacker can obtain agent access and permissions intended for the spoofed user. This issue is resolved in version 2026.5.7.
Affected products
- openclaw openclaw < 2026.5.7
Timeline
- 2026-05-28: advisory: Original advisory GHSA-cw4q-gqg5-g38h published
- 2026-06-16: disclosed: CVE-2026-53849 published
- 2026-06-18: patched: Duplicate advisory withdrawn and fix confirmed in 2026.5.7