Policy Enforcement Vulnerability in OpenClaw Affects Zalo's AllowFrom Feature
CVE-2026-53857
8.6HIGH
What is CVE-2026-53857?
A policy enforcement vulnerability exists in OpenClaw prior to version 2026.5.3, affecting its integration with Zalo messaging. The issue lies in the handling of mutable display metadata, which can cause mismatched allowFrom policy entries when display names are altered. This can potentially enable attackers to access responses intended for different Zalo identities, jeopardizing user privacy and data integrity.
Affected Version(s)
OpenClaw 0 < 2026.5.3
OpenClaw 2026.5.3
