High severity8.8NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-53811
CVE-2026-53811
Description
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-7hxm-f538-3xp6nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-privilege-escalation-via-mutable-display-names-in-matrix-allowfromnvdThird Party Advisory
News mentions
1- OpenClaw: 14 Vulnerabilities Disclosed in Single Batch, Including Code Execution and Privilege EscalationVypr Intelligence · Jun 11, 2026