CVE-2026-28464Disclosure(openclaw / openclaw)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit timing side-channels across multiple requests to gradually determine the authentication token.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-05); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-07: 1Mentions · 2026-03-09: 1Mentions · 2026-03-13: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-13: 103-0503-0703-0903-13
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • Wasteland@wastelandweekly
    Disclosure

    CVE-2026-28464: researchers found that OpenClaw's agent fails to validate user intent before executing high-risk shell ops. Arbitrary code execution via prompt injection. AI agents running with root-level trust is a design choice. A bad one.

    Post summary

    Researchers have identified CVE-2026-28464, where OpenClaw’s agent allows arbitrary code execution through prompt injection due to missing intent validation for high‑risk shell operations.

    0000047
    6 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenClaw, Timing Side-Channel, #CVE-2026-28464 (Medium) https://dailycve.com/openclaw-timing-side-channel-cve-2026-28464-medium/

    Post summary

    The tweet announces the Medium-rated Timing Side-Channel vulnerability (CVE-2026-28464) in OpenClaw, without any evidence of exploitation, PoC, or patch information.

    0000024
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28464 OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements… https://www.cve.org/CVERecord?id=CVE-2026-28464

    Post summary

    The post describes a timing‑based validation flaw in OpenClaw affecting versions before 2026.2.12, indicating the vulnerability’s type and the version that resolves it.

    00000142
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28464: CRITICAL] Vulnerable OpenClaw versions allow remote attackers to infer authentication tokens through timing side-channels in hook token validation, posing a cybersecurity risk.#cve,CVE-2026-28464,#cybersecurity https://cvefind.com/CVE-2026-28464

    Post summary

    The tweet announces a critical timing side‑channel vulnerability in OpenClaw that lets attackers infer authentication tokens.

    0000073
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more