VYPR
Medium severity6.5NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026

CVE-2026-53815

CVE-2026-53815

Description

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensitive channel messages.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • OpenClaw/Openclawinferred2 versions
    <2026.5.19+ 1 more
    • (no CPE)range: <2026.5.19
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: <2026.5.19

Patches

Vulnerability mechanics

References

2

News mentions

2
CVE-2026-53815 · Medium · VYPR