CVE-2026-28475
- EPSS 0.28%
- Veröffentlicht 05.03.2026 21:59:50
- Zuletzt bearbeitet 11.03.2026 16:17:15
OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit timing side...
CVE-2026-28473
- EPSS 0.28%
- Veröffentlicht 05.03.2026 21:59:49
- Zuletzt bearbeitet 11.03.2026 16:18:20
OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests by sending the /approve chat command. The /approve command path invokes exec.approval...
CVE-2026-28474
- EPSS 0.49%
- Veröffentlicht 05.03.2026 21:59:49
- Zuletzt bearbeitet 17.09.2026 18:16:40
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud di...
CVE-2026-28472
- EPSS 0.35%
- Veröffentlicht 05.03.2026 21:59:48
- Zuletzt bearbeitet 09.03.2026 20:40:40
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without provi...
CVE-2026-28471
- EPSS 0.23%
- Veröffentlicht 05.03.2026 21:59:47
- Zuletzt bearbeitet 11.03.2026 16:18:31
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver va...
CVE-2026-28470
- EPSS 0.48%
- Veröffentlicht 05.03.2026 21:59:46
- Zuletzt bearbeitet 25.03.2026 15:16:40
OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. Attackers can bypass the allowlist protection...
CVE-2026-28469
- EPSS 0.3%
- Veröffentlicht 05.03.2026 21:59:45
- Zuletzt bearbeitet 09.03.2026 20:29:33
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-...
CVE-2026-28468
- EPSS 0.14%
- Veröffentlicht 05.03.2026 21:59:44
- Zuletzt bearbeitet 11.03.2026 16:00:31
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests without requiring gateway authentication, allowing local attackers to access browser control endpoints. A ...
CVE-2026-28467
- EPSS 0.4%
- Veröffentlicht 05.03.2026 21:59:43
- Zuletzt bearbeitet 09.03.2026 15:28:05
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch arbitrary HTTP(S) URLs. Attackers who can influence media URLs through model-controlle...
CVE-2026-28466
- EPSS 0.42%
- Veröffentlicht 05.03.2026 21:59:42
- Zuletzt bearbeitet 09.03.2026 15:30:16
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attac...