Medium severity4.3NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-53835
CVE-2026-53835
Description
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploit this by leveraging the dynamic-agent binding feature to change sender-agent binding state beyond intended policy, potentially enabling unauthorized binding modifications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-3wqp-prf6-2m72nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-config-write-enforcement-bypass-in-feishu-dynamic-agent-bindingsnvdThird Party Advisory
News mentions
1- OpenClaw: 25 CVEs Disclosed in Largest Security Batch, Including Code Execution and Critical Auth BypassVypr Intelligence · Jun 12, 2026