CVE-2026-28466Disclosure(openclaw / openclaw)

MEDIUMCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attackers with valid gateway credentials can inject approval control fields to execute arbitrary commands on connected node hosts, potentially compromising developer workstations and CI runners.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-06); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-07: 2Mentions · 2026-03-09: 2Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-04-01: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 203-0503-0603-0703-0904-01
Signal classification4 categories
Disclosure
450.0%
Patch
225.0%
General
112.5%
PoC
112.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-051
Patch1
2026-03-062
General1Patch1
2026-03-072
Disclosure2
2026-03-092
Disclosure2
2026-04-011
PoC1
Full discourse8 posts
  • Clandestine@akaclandestine
    PoC

    GitHub - Orioning/CVE-2026-28466: CVE-2026-28466复现脚本 · GitHub https://github.com/Orioning/CVE-2026-28466

    Post summary

    The GitHub repo offers a reproduction script for CVE-2026-28466, serving as a proof‑of‑concept that demonstrates the vulnerability.

    14017122.5K
    61.1K followersView on X
  • maru@maru1151157
    Disclosure

    🚨 CVE-2026-28466 (CVSS: 9.9) OpenClaw 2026.2.14以前では、ゲートウェイがnode.invokeパラメータの内部承認フィールドを検証せず、認証クライアントがhttp://system.runコマンドの承認回避可能。攻撃者は任意コマンド実行可能で、開発ワークステーションやCIランナーを侵害の危険にさらす。 https://maruomosquit.com/vulnerability/CVE-2026-28466/ #脆弱性 #セキュリティ

    Post summary

    The post discloses that OpenClaw versions prior to 2026.2.14 allow authenticated users to bypass internal approval of the node.invoke parameter, enabling arbitrary command execution via the system.run command, with a CVSS score of 9.9.

    02080167
    1.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 7 Critical vulnerabilties in #OpenClaw #NextCloud talk plugin #CVE-2026-28474 #CVE-2026-28466 #CVE-2026-28391 #CVE-2026-28446 #CVE-2026-28470 #CVE-2026-28472 #CVE-2026-28484 CVSS: 9.3-9.2. Update to 2026.2.6 or later https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-openclaws-nextcloud-talk-plugin-patch #Patch

    Post summary

    A warning alerts to seven critical CVEs in the OpenClaw NextCloud talk plugin, provides high CVSS scores, and recommends updating to patch version 2026.2.6 or later.

    02021381
    7.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28466: OpenClaw < 2026.2.14 - Remote Co... Gateway approval bypass turns any OpenClaw creds into full RCE on connected nodes - dev workstations and CI runners are... https://zerodaysignal.com/vulnerability/CVE-2026-28466 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses CVE‑2026‑28466, a gateway approval bypass in OpenClaw that lets attackers achieve full remote code execution on connected nodes, but it provides no PoC, exploit code, or patch information.

    0001088
    140 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28466 OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing… https://www.cve.org/CVERecord?id=CVE-2026-28466

    Post summary

    CVE-2026-28466 reveals a gateway flaw in OpenClaw that does not sanitize internal approval fields, potentially enabling exploitation.

    00000171
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28466 - Critical OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated client... https://www.thehackerwire.com/vulnerability/CVE-2026-28466/ https://t.co/sIeDojmu2z

    Post summary

    CVE-2026-28466 describes a critical gateway flaw in OpenClaw that permits authenticated clients to send unsanitized node.invoke parameters; updating to 2026.2.14 resolves the vulnerability.

    0000052
    128 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-28466 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28466-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28466 #openclaw #

    Post summary

    The post merely announces CVE-2026-28466 for OpenClaw and links to an external alert, providing no further technical details, PoC, exploits, or mitigation information.

    00000128
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28466: HIGH] Security advisory: OpenClaw < 2026.2.14 has a critical flaw allowing authenticated clients to bypass exec approval gating, executing commands on connected hosts. Update ASAP.#cve,CVE-2026-28466,#cybersecurity https://cvefind.com/CVE-2026-28466

    Post summary

    OpenClaw versions prior to 2026.2.14 are vulnerable to authenticated remote code execution through an exec approval bypass, and an urgent patch is required.

    0000083
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more