Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-53830— OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload

CVSS 6.5 · Medium EPSS 0.21% · P11

Possible ATT&CK Techniques 1AI

T1114 · Email Collection

Affected Version Matrix 2

VendorProductVersion RangeStatus
OpenClawOpenClaw< 2026.4.22affected
2026.4.22unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-53830

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
Source: NVD (National Vulnerability Database)
Vulnerability Description
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
不充分的会话过期机制
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenClaw 会话机制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenClaw是OpenClaw团队开源的一个智能人工助理。 OpenClaw 2026.4.22之前版本存在会话机制问题漏洞,该漏洞源于secrets.reload后旧Slack和Zalo webhook密钥未被正确撤销,可能导致攻击者在操作者预期吊销密钥后仍利用旧密钥窗口发送webhook事件,可能接受之前凭据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
OpenClawOpenClaw 0 ~ 2026.4.22 -

II. Public POCs for CVE-2026-53830

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53830

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53830 (2)

Same Patch Batch · OpenClaw · 2026-06-12 · 20 CVEs total

CVE-2026-538389.8 CRITICALOpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection
CVE-2026-538228.8 HIGHOpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval an
CVE-2026-538368.8 HIGHOpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases
CVE-2026-538218.8 HIGHOpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket
CVE-2026-538288.8 HIGHOpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement
CVE-2026-538318.3 HIGHOpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin Allo
CVE-2026-538238.1 HIGHOpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom
CVE-2026-538298.0 HIGHOpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
CVE-2026-538337.7 HIGHQQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command
CVE-2026-538327.7 HIGHOpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration
CVE-2026-538347.5 HIGHOpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands
CVE-2026-538206.6 MEDIUMOpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn
CVE-2026-538256.5 MEDIUMOpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write
CVE-2026-538246.5 MEDIUMMattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via Monitor Refres
CVE-2026-538276.5 MEDIUMOpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.acti
CVE-2026-538396.5 MEDIUMOpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
CVE-2026-538264.3 MEDIUMOpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn
CVE-2026-538354.3 MEDIUMOpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings
CVE-2026-538373.7 LOWOpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers

IV. Related Vulnerabilities

V. Comments for CVE-2026-53830

No comments yet


Leave a comment