CVE-2026-28454Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the webhook endpoint that trust attacker-controlled JSON payloads. Remote attackers can forge Telegram updates by spoofing message.from.id and chat.id fields to bypass sender allowlists and execute privileged bot commands.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-07: 103-0503-0603-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-28454 OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the we… https://www.cve.org/CVERecord?id=CVE-2026-28454

    Post summary

    CVE-2026-28454 enables unauthenticated POST requests by failing to validate Telegram webhook secrets; the issue is resolved by upgrading to OpenClaw 2026.2.2.

    00000159
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-28454 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28454-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28454 #openclaw #

    Post summary

    The tweet provides a link to a CVE alert page announcing CVE-2026-28454 for OpenClaw, but does not include technical details, PoC, or exploitation claims.

    0000085
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28454: CRITICAL] Critical security flaw in older OpenClaw versions (pre-2026.2.2) enables unauthenticated HTTP POST requests via Telegram webhook mode. Attackers can forge messages to execute privi...#cve,CVE-2026-28454,#cybersecurity https://cvefind.com/CVE-2026-28454

    Post summary

    The post announces a critical flaw in older OpenClaw versions that allows unauthenticated POST requests through Telegram webhooks, potentially enabling attackers to forge messages.

    0000077
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more