Sender Policy Bypass Vulnerability in OpenClaw's BlueBubbles
CVE-2026-53860
2.3LOW
What is CVE-2026-53860?
A vulnerability in OpenClaw's BlueBubbles prior to version 2026.5.7 allows attackers to exploit the system through conversation metadata. Instead of relying on a stable sender identity, the vulnerability permits the manipulation of conversation-level identifiers. This enables malicious participants to match their identifiers with allowlist entries, effectively bypassing established access controls intended to safeguard sensitive agent responses.
Affected Version(s)
OpenClaw 0 < 2026.5.7
OpenClaw 2026.5.7
