CVE-2026-53823

HIGH

OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-c29c-2q9c-pc86)
https://github.com/openclaw/openclaw/security/advisories/GHSA-c29c-2q9c-pc86
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom
https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-slack-display-names-in-allowfrom

Scores

CVSS v3 8.1
EPSS 0.0021
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (2)
OpenClaw/OpenClaw < 2026.5.3
OpenClaw/OpenClaw 2026.5.3
Published Jun 12, 2026
Tracked Since Jun 13, 2026