CVE-2026-53860
EUVD-2026-3716216.06.2026, 19:17
OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender identity. Attackers can influence conversation-level identifiers to receive agent responses intended for configured senders, potentially bypassing access controls.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openclaw | openclaw | 𝑥 < 2026.5.7 |
| openclaw | openclaw | 2026.5.7:beta1 |
𝑥
= Vulnerable software versions