๐Ÿ” CVE Alert

CVE-2026-53823

HIGH 8.1

OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.

CWE CWE-290
Vendor openclaw
Product openclaw
Published Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw

Be the first to know when new high vulnerabilities affecting openclaw openclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

OpenClaw / OpenClaw
0 < 2026.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-c29c-2q9c-pc86 vulncheck.com: https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-slack-display-names-in-allowfrom

Credits

๐Ÿ” Philip (@PhilipPhil)