LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-53857

openclaw · openclaw

Published
CVSS8.1
Severityhigh
WeaknessCWE-290
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent responses intended for different Zalo identities when the feature is enabled.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53857

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53857.