OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions
CVE-2026-53815
7.1HIGH
What is CVE-2026-53815?
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensitive channel messages.
Affected Version(s)
OpenClaw 0 < 2026.5.19
OpenClaw 2026.5.19
