HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53807Published Modified CNA VulnCheck

CVE-2026-53807: OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.

Metrics

CVSS v4.0
7.7
Severity
HIGH
Fixed in
2026.5.6
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authorization bypass vulnerability exists in OpenClaw, a Telegram bot framework, affecting all versions before 2026.5.6. The flaw is reachable over the network and requires a low-privilege account; an attacker sends crafted Telegram interactive callbacks that mark themselves as an authorized sender before the commands.allowFrom allowlist check runs. Successful exploitation lets the attacker invoke any restricted command as if they were a permitted sender, enabling full read, write, and availability impact on the affected service. A patched-image rebuild at version 2026.5.6 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-53807 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle OpenClaw. Affected image layers are flagged in both registry scans and CI pipeline checks before deployment.

Available
Triage

HarborGuard scores this CVE at 7.7 HIGH using the CVSS v4.0 vector and weights that score against each customer environment's compliance policy to surface urgency appropriately. Triage findings are routed to the relevant team inbox within the customer org based on configured ownership rules.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.6 is available on HarborGuard for any environment where an affected version is detected. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the OpenClaw service over the network to deliver crafted Telegram callback payloads.

  • AuthenticationRequired

    A low-privilege Telegram account is sufficient; no admin or elevated credentials are needed, but some account access is required.

  • Victim interactionNot required

    No victim action is needed; the attacker sends the crafted callback directly without any social-engineering step.

  • Attack complexityDetail

    Base exploit logic is condition-free and reliable, though the AT:P token indicates that specific deployment conditions (such as particular allowFrom configurations) must be present for the bypass to succeed.

Blast Radius

  • Reads any data the Telegram bot has access to, including stored messages, user records, and connected service credentials.
  • Modifies bot state and persisted configuration by invoking write-capable commands outside the intended allowlist.
  • Triggers command handlers that can disrupt or crash the affected OpenClaw service process.
  • Bypasses operator-defined sender restrictions entirely, effectively nullifying the commands.allowFrom access control for the attacker's session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-53807 is active for all scanned images the moment the advisory is ingested, covering registry images and images built in CI pipelines. For environments running OpenClaw below 2026.5.6, a rebuilt image at the patched version is available. Customers with auto-remediation enabled receive a rebuilt image, a regression-test run, and a PR opened against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in those environments. Where compliance policy requires manual review before merging, HarborGuard queues the PR and surfaces it in the triage dashboard with the CVSS score and affected image list attached.

See how HarborGuard automates this

Fix available

2026.5.6
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.6 (from 0)
    Fixed in 2026.5.6
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N