
CVE-2026-28454 OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the we… https://www.cve.org/CVERecord?id=CVE-2026-28454
Post summary
CVE-2026-28454 enables unauthenticated POST requests by failing to validate Telegram webhook secrets; the issue is resolved by upgrading to OpenClaw 2026.2.2.


