LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-53833

openclaw · openclaw

Published
CVSS7.7
Severityhigh
WeaknessCWE-290
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the affected command without non-wildcard allowlist entry requirements.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53833

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53833.