HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53857Published Modified CNA VulnCheck

CVE-2026-53857: OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent responses intended for different Zalo identities when the feature is enabled.

Metrics

CVSS v4.0
8.6
Severity
HIGH
Fixed in
2026.5.3
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a policy enforcement vulnerability in OpenClaw, affecting versions before 2026.5.3. An authenticated attacker over the network can manipulate a mutable Zalo contact display name to match an allowFrom policy entry, causing the system to treat them as a trusted identity. Successful exploitation lets the attacker receive agent responses intended for a different Zalo identity, disclosing sensitive message content and enabling unauthorized message injection. A patched-image rebuild at version 2026.5.3 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-53857 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle OpenClaw.

Available
Triage

HarborGuard scores this CVE at CVSS 8.6 HIGH and is capable of weighting that score against each environment's compliance policy to surface prioritized findings routed to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild at OpenClaw 2026.5.3 is available on HarborGuard for any environment where an affected version is detected. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The vulnerable OpenClaw service must be reachable over the network; the attacker sends crafted requests from a remote host.

  • AuthenticationRequired

    The attacker must hold a low-privilege account (a valid Zalo contact identity) sufficient to trigger the allowFrom policy matching logic.

  • Victim interactionNot required

    No victim action is needed; the attacker manipulates their own display name and the policy matching occurs server-side without any user interaction.

  • Attack complexityDetail

    Attack complexity is low; the exploit requires no race conditions or special environmental conditions, only a deliberate display name change to match a policy entry.

Blast Radius

  • The attacker reads agent response messages intended for a different, legitimate Zalo identity, disclosing potentially sensitive conversation content.
  • The attacker receives authorized agent replies as if they were a trusted identity, effectively impersonating that identity within the Zalo integration.
  • Confidentiality and integrity of the affected Zalo channel are both compromised; the legitimate identity may be silently denied responses that were redirected to the attacker.

How HarborGuard Handles This

Available on HarborGuard: detection of this CVE fires against any image containing OpenClaw below 2026.5.3, matched within minutes of the advisory publication. A patched-image rebuild at 2026.5.3 is available immediately for affected environments. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression run, and opens a PR against affected workloads; for HIGH-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a diff summary are staged for engineer review. Until a rebuild is deployed, compensating controls worth considering include restricting the Zalo allowFrom feature to environments where it is strictly necessary, enforcing strict immutable-identity binding at the integration layer, and applying network policy to limit which services can invoke the OpenClaw agent endpoint.

See how HarborGuard automates this

Fix available

2026.5.3
Affected packages
  • OpenClaw / OpenClaw
    < 2026.5.3 (from 0)
    Fixed in 2026.5.3
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N