Improper access control in OpenClaw - CVE-2026-28469

 

Improper access control in OpenClaw - CVE-2026-28469

Published: May 4, 2026


Vulnerability identifier: #VU129464
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28469
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause cross-account policy-context misrouting.

The vulnerability exists due to improper access control in extensions/googlechat/src/monitor.ts when routing inbound Google Chat webhook events on a shared HTTP path. A remote attacker can send a valid webhook request that matches more than one registered target to cause cross-account policy-context misrouting.

Exploitation requires multiple Google Chat webhook targets to be registered on the same path and request verification to succeed for more than one target.


Affected software

OpenClaw

How to mitigate CVE-2026-28469

Install security update from vendor's website.

OpenClaw - update to 2026.2.14

External References

Related Security Bulletins