CVE-2026-28392Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message sender when dmPolicy is set to open (must be configured). Attackers can execute privileged slash commands via direct message to bypass allowlist and access-group restrictions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-07)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-07: 203-0503-0603-07
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-061
General1
2026-03-072
Disclosure1Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28392 OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message se… https://www.cve.org/CVERecord?id=CVE-2026-28392

    Post summary

    The text announces a privilege escalation vulnerability in OpenClaw’s Slack integration, affecting earlier versions, without mentioning any active exploitation, exploitation tools, or current patches.

    00010186
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28392: CRITICAL] Critical privilege escalation vulnerability found in OpenClaw versions pre-2026.2.14 enables attackers to execute privileged slash commands through direct messages, bypassing acces...#cve,CVE-2026-28392,#cybersecurity https://cvefind.com/CVE-2026-28392

    Post summary

    The tweet announces the discovery of CVE‑2026‑28392, a critical privilege‑escalation vulnerability in OpenClaw versions prior to 2026.2.14 that lets attackers run privileged slash commands through direct messages.

    0001069
    596 followersView on X
  • Renan Santos@renandnzsantos
    Patch

    The vulnerabilities (all patched in 2026.2.21): • CVE-2026-28393: Path traversal in hook transform module loading → arbitrary JavaScript execution • CVE-2026-28392: Privilege escalation in Slack slash-command handler → any DM sender could escalate • CVE-2026-28391: cmd.exe metacharacter injection in allowlist-gated exec requests • CVE-2026-28394: DoS in web_fetch tool via memory exhaustion

    Post summary

    The post reports four newly disclosed CVEs with detailed technical characteristics and confirms that all are patched as of 2026.2.21.

    0000014
    40 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-28392 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28392-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28392 #openclaw #

    Post summary

    The tweet announces CVE-2026-28392 in OpenClaw with a link and hashtags but offers no further technical or exploitation details.

    0000074
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more