CVE-2026-28391Disclosure(openclaw / openclaw)

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can craft command strings with shell metacharacters like & or %...% to execute unapproved commands beyond the allowlisted operations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-07); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-07: 3Mentions · 2026-03-10: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 3Technical Details · 2026-03-10: 103-0503-0603-0703-10
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-062
Patch2
2026-03-073
Disclosure2Patch1
2026-03-101
Disclosure1
Full discourse7 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 7 Critical vulnerabilties in #OpenClaw #NextCloud talk plugin #CVE-2026-28474 #CVE-2026-28466 #CVE-2026-28391 #CVE-2026-28446 #CVE-2026-28470 #CVE-2026-28472 #CVE-2026-28484 CVSS: 9.3-9.2. Update to 2026.2.6 or later https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-openclaws-nextcloud-talk-plugin-patch #Patch

    Post summary

    Seven critical CVEs (CVE-2026-28474, CVE-2026-28466, CVE-2026-28391, CVE-2026-28446, CVE-2026-28470, CVE-2026-28472, CVE-2026-28484) affecting the OpenClaw NextCloud talk plugin are disclosed with CVSS 9.2–9.3; users are advised to update to version 2026.2.6 or later per the vendor advisory.

    02021381
    7.2K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28391: CRITICAL] OpenClaw (pre-2026.2.2) overlooks Windows cmd.exe metacharacter validation, enabling attackers to circumvent command restrictions, allowing unauthorized executions.#cve,CVE-2026-28391,#cybersecurity https://cvefind.com/CVE-2026-28391

    Post summary

    The tweet discloses CVE‑2026‑28391, a critical flaw in OpenClaw that bypasses cmd.exe metacharacter checks to allow unauthorized command execution. No proof of concept, exploit, patch, or evidence of active exploitation is mentioned.

    01020166
    596 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28391: OpenClaw < 2026.2.2 - Command In... Classic cmd.exe metacharacter bypass turns allowlists into suggestions - & and %var% expansion slip past validation lik... https://zerodaysignal.com/vulnerability/CVE-2026-28391 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new vulnerability, CVE-2026-28391, affecting OpenClaw versions prior to 2026.2.2, is disclosed; it involves a classic cmd.exe metacharacter bypass that slips past allow‑list validation, potentially enabling command injection.

    0000053
    142 followersView on X
  • Renan Santos@renandnzsantos
    Patch

    The vulnerabilities (all patched in 2026.2.21): • CVE-2026-28393: Path traversal in hook transform module loading → arbitrary JavaScript execution • CVE-2026-28392: Privilege escalation in Slack slash-command handler → any DM sender could escalate • CVE-2026-28391: cmd.exe metacharacter injection in allowlist-gated exec requests • CVE-2026-28394: DoS in web_fetch tool via memory exhaustion

    Post summary

    A disclosure of multiple CVEs, summarizing their technical weaknesses and indicating that they were patched with the 2026.2.21 release.

    0000014
    40 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28391 OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing at… https://www.cve.org/CVERecord?id=CVE-2026-28391

    Post summary

    The statement announces a vulnerability (CVE-2026-28391) in OpenClaw where improper validation of cmd.exe metacharacters could lead to code execution, but it provides no evidence of PoC, exploit tools, active use, or remediation steps.

    00000208
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28391 - Critical OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass com... https://www.thehackerwire.com/vulnerability/CVE-2026-28391/ https://t.co/pN0kgoVKN6

    Post summary

    The post discloses a critical vulnerability (CVE‑2026‑28391) in OpenClaw where earlier versions improperly validate Windows cmd.exe metacharacters during allowlist‑gated exec requests, potentially allowing bypass of restrictions.

    0000044
    128 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: WordPress themes and OpenClaw stack (CVSS 9.8-9.9) Affected: zozothemes Lendiz; zozothemes Nutrie; Nginx UI; OpenClaw Internet-facing exposure dominates, led by WordPress themes and OpenClaw components; fixes and mitigations below. • CVE-2025-68553 (CVSS 9.9) Lendiz WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server. • CVE-2025-68555 (CVSS 9.9) Nutrie WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server. • CVE-2026-27944 (CVSS 9.8) Nginx UI prior to 2.3.3 has an unauthenticated /api/backup endpoint that discloses the encryption keys required to decrypt backups via the X-Backup-Security header. • CVE-2026-28391 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, enabling remote command execution. • CVE-2026-28470 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 contain an exec approvals allowlist bypass that enables attackers to execute arbitrary commands by injecting command substitution syntax. 🛠️ Action • Patch/upgrade to the fixed versions called out by vendors and advisories for Lendiz, Nutrie, Nginx UI, and OpenClaw. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply stated mitigations and reduce exposure (disable vulnerable features/modules, restrict access). • Add detections for exploitation patterns (web shells, file-write paths, auth anomalies, command substitutions). • Hunt for indicators around the affected services during the disclosure window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces several high‑CVSS WordPress and OpenClaw vulnerabilities, detailing their technical mechanisms and providing patch/mitigation guidance.

    00000130
    85 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more