CVE-2026-53833: QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the affected command without non-wildcard allowlist entry requirements.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QQBot for OpenClawto a version that resolves this vulnerability.Fixed in 2026.4.29
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53833?
CVE-2026-53833 has a severity rating of 7.4, classified as high risk.
How do I fix CVE-2026-53833?
To resolve CVE-2026-53833, update OpenClaw to version 2026.4.29 or later.
What type of vulnerability is CVE-2026-53833?
CVE-2026-53833 is an authorization bypass vulnerability affecting the QQBot streaming command.
Who is affected by CVE-2026-53833?
Users of OpenClaw QQBot versions prior to 2026.4.29 are affected by CVE-2026-53833.
What could an attacker do with CVE-2026-53833?
An attacker could modify the QQBot streaming configuration, bypassing intended admin policies.