{"id":"CVE-2026-53815","aliases":["GHSA-q7q8-3mgw-q67r"],"url":"https://o3.security/vulnerability/CVE-2026-53815","summary":"OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions","details":"OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensitive channel messages.","published":"2026-06-11T20:08:52.351Z","modified":"2026-08-12T03:51:32.127504436Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.5.19"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53815.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-q7q8-3mgw-q67r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53815"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-channel-allowlist-bypass-in-message-read-actions"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.127504436Z"}}