CVE-2026-53839: medium-severity vulnerability in OpenClaw
OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
OpenClaw before version 2026.5.7 has a flaw where it accepts hostnames that start with a trusted name instead of matching exactly, allowing attackers to trick the system into sending login credentials to fake servers.
The vulnerability stems from incomplete hostname validation in retry endpoint checks (CWE-1023), where prefix matching is used instead of exact string comparison. An attacker can craft a malicious hostname with a trusted prefix to intercept authentication material sent during retry operations, requiring network positioning to exploit.
In the same product, most dangerous first.