LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-53834

openclaw · openclaw

Published
CVSS7.5
Severityhigh
WeaknessCWE-863
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control policies are applied, potentially triggering command handling from blocked senders depending on operator configuration.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53834

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53834.