High severity8.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-53807
CVE-2026-53807
Description
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-w5ww-7chg-mxcqnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-authorization-bypass-in-telegram-interactive-callbacks-via-commands-allowfromnvdThird Party Advisory
News mentions
1- OpenClaw: 14 Vulnerabilities Disclosed in Single Batch, Including Code Execution and Privilege EscalationVypr Intelligence · Jun 11, 2026