CVE-2026-53837
LOW
NVD
CVSS Score
3.7
Severity
LOW
Published
Jun 12, 2026
Vendor
unknown
Description
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events missing channel type information to process restricted content.