CVE-2026-53835: OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploit this by leveraging the dynamic-agent binding feature to change sender-agent binding state beyond intended policy, potentially enabling unauthorized binding modifications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53835?
The severity of CVE-2026-53835 is classified as low with a score of 2.3.
What does CVE-2026-53835 affect?
CVE-2026-53835 affects OpenClaw versions before 2026.5.6, specifically in the Feishu dynamic-agent bindings.
What is the nature of the vulnerability described in CVE-2026-53835?
CVE-2026-53835 is a configuration enforcement bypass vulnerability that allows authenticated users to create or update bindings without following the configured controls.
How can I fix CVE-2026-53835?
To fix CVE-2026-53835, upgrade OpenClaw to version 2026.5.6 or later.
Who can exploit CVE-2026-53835?
Authenticated senders can exploit CVE-2026-53835 to bypass the config-write controls.