Authentication Bypass by Spoofing in OpenClaw - CVE-2026-28480
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to authentication bypass by spoofing in the Telegram allowlist authorization mechanism when matching allowlist entries against mutable @username values instead of immutable numeric sender IDs. A remote attacker can use a recycled or reassigned Telegram username to bypass authorization checks.
This issue affects deployments that rely on Telegram allowlists as strict identity controls.