Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3191 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-53851PATCHED
openclaw · openclaw

OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass

Description

A vulnerability classified as problematic was found in OpenClaw up to 2026.5.11. Affected is an unknown function of the component Notifications Handler. Executing a manipulation can lead to missing authorization. This vulnerability is tracked as CVE-2026-53851. The attack can be launched remotely.

Affected Products

VendorProductVersions
openclawopenclawnpm/openclaw: <= 2026.5.7

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-fcvx-5cxc-v5p8(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-slack-reaction-event-notification-bypass(third-party-advisory)

Related News (1 articles)

Tier C
VulDB11d ago
CVE-2026-53851 | OpenClaw up to 2026.5.11 Notifications authorization (GHSA-fcvx-5cxc-v5p8)
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
openclaw@2026.5.12
CWECWE-285
PublishedJun 16, 2026
Last enriched11d agov2
Trending Score8
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVEEXP
Emerging AI Supply Chain Threat in OpenClaw's Skill Marketplace
Trending: 26
HIGHCVE-2026-53866EXP
OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing
Trending: 9
HIGHCVE-2026-53865EXP
OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH
Trending: 9
HIGHCVE-2026-53853EXP
OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS
Trending: 9
HIGHCVE-2026-53843EXP
OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 16, 2026
Patch Available
Jun 16, 2026
Discovered by ZDM
Jun 16, 2026
Updated: description, severity, cvssEstimate, cweIds
Jun 16, 2026

Version History

v2
Last enriched 11d ago
v2Tier C11d ago

Updated description with new technical details, changed severity to HIGH, set CVSS estimate to 7.5, added CWE-287, and corrected exploit availability status.

descriptionseveritycvssEstimatecweIds
via VulDB
v111d ago

Initial creation