Improper access control in OpenClaw - CVE-2026-28474
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass DM or room allowlists.
The vulnerability exists due to improper access control in the allowlist matching logic when processing Nextcloud Talk webhook payloads. A remote user can change their Nextcloud display name to match an allowlisted user ID to bypass DM or room allowlists.
Only the separately installed optional Nextcloud Talk plugin is affected; core OpenClaw is not impacted unless this plugin is installed and used.