← العودة للجدول
CVE-2026-53807
CVE-2026-53807 — OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Teleg
📅 2026-06-11
🟠 High 🔥 No NVD Exploit Vulnerability CVSS 8.8

📋 الوصف الكامل

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-53807

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-53807 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←