Improper access control in OpenClaw - CVE-2026-28392
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute privileged slash commands.
The vulnerability exists due to improper access control in the Slack slash-command handler when processing direct messages with dmPolicy=open. A remote user can send a direct message containing a slash command to execute privileged slash commands.
Only deployments with Slack direct messages enabled and channels.slack.dm.policy set to open are vulnerable.