Security Advisory

CVE-2026-53839

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-12 21:57:01
Last updated 2026-07-14 21:33:45
Assigner VulnCheck
CVSS score 6.0
State PUBLISHED

Description

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.