OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the affected command without non-wildcard allowlist entry requirements.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-jvm4-4j77-39p6 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-qqbot-streaming-command | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-12 22:16
Updated : 2026-07-23 09:10
NVD link : CVE-2026-53833
Mitre link : CVE-2026-53833
CVE.ORG link : CVE-2026-53833
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-290
Authentication Bypass by Spoofing
