OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers
CVE-2026-53837

6.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-53837?

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events missing channel type information to process restricted content.

Affected Version(s)

OpenClaw 0 < 2026.5.6

OpenClaw 2026.5.6

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
qclawer
.