CVE-2026-28470Disclosure(openclaw / openclaw)

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. Attackers can bypass the allowlist protection by embedding unescaped $() or backticks inside double-quoted strings to execute unauthorized commands.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-06); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-05: 1Mentions · 2026-03-06: 4Mentions · 2026-03-07: 1Mentions · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-17: 1Patch / Workaround · 2026-03-06: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-07: 1Technical Details · 2026-03-17: 103-0503-0603-0703-17
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-064
Disclosure3Patch1
2026-03-071
Disclosure1
2026-03-171
Disclosure1
Full discourse7 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 7 Critical vulnerabilties in #OpenClaw #NextCloud talk plugin #CVE-2026-28474 #CVE-2026-28466 #CVE-2026-28391 #CVE-2026-28446 #CVE-2026-28470 #CVE-2026-28472 #CVE-2026-28484 CVSS: 9.3-9.2. Update to 2026.2.6 or later https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-openclaws-nextcloud-talk-plugin-patch #Patch

    Post summary

    Seven critical vulnerabilities in the OpenClaw NextCloud Talk plugin have been disclosed; users are advised to update to version 2026.2.6 or later to mitigate the CVEs.

    02021381
    7.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28470: OpenClaw < 2026.2.2 - Exec Allow... Command substitution in double quotes turns OpenClaw's exec allowlist into a suggestion box - `"$(rm -rf /)"` laughs at... https://zerodaysignal.com/vulnerability/CVE-2026-28470 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑28470 in OpenClaw, showing a command‑substitution technique that bypasses the exec allowlist, effectively disclosing the vulnerability and demonstrating a proof‑of‑concept.

    0000078
    155 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28470 OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by … https://www.cve.org/CVERecord?id=CVE-2026-28470

    Post summary

    The note announces that OpenClaw versions before 2026.2.2 have an allowlist bypass allowing arbitrary command execution, but provides no PoC, patch, or exploit details.

    00000146
    56.6K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for OpenClaw (CVE-2026-28470) https://vuldb.com/?id.349397

    Post summary

    The statement announces that a new vulnerability, CVE-2026-28470, targeting OpenClaw has been disclosed with higher severity, referencing a VulDB entry.

    0000086
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28470 - Critical OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command sub... https://www.thehackerwire.com/vulnerability/CVE-2026-28470/ https://t.co/JEmqyHmSZe

    Post summary

    The tweet discloses a critical vulnerability (CVE‑2026‑28470) in OpenClaw that allows arbitrary command execution via an allowlist bypass, but provides no proof of concept, exploit code, or mitigation.

    0000070
    125 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: WordPress themes and OpenClaw stack (CVSS 9.8-9.9) Affected: zozothemes Lendiz; zozothemes Nutrie; Nginx UI; OpenClaw Internet-facing exposure dominates, led by WordPress themes and OpenClaw components; fixes and mitigations below. • CVE-2025-68553 (CVSS 9.9) Lendiz WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server. • CVE-2025-68555 (CVSS 9.9) Nutrie WordPress theme (zozothemes) contains an unrestricted file upload vulnerability that could allow an attacker to upload a web shell to the server. • CVE-2026-27944 (CVSS 9.8) Nginx UI prior to 2.3.3 has an unauthenticated /api/backup endpoint that discloses the encryption keys required to decrypt backups via the X-Backup-Security header. • CVE-2026-28391 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, enabling remote command execution. • CVE-2026-28470 (CVSS 9.8) OpenClaw versions prior to 2026.2.2 contain an exec approvals allowlist bypass that enables attackers to execute arbitrary commands by injecting command substitution syntax. 🛠️ Action • Patch/upgrade to the fixed versions called out by vendors and advisories for Lendiz, Nutrie, Nginx UI, and OpenClaw. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply stated mitigations and reduce exposure (disable vulnerable features/modules, restrict access). • Add detections for exploitation patterns (web shells, file-write paths, auth anomalies, command substitutions). • Hunt for indicators around the affected services during the disclosure window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post details multiple high‑CVSS vulnerabilities across WordPress themes and OpenClaw, provides technical specifics and patch guidance, but does not include PoC, exploit code, or evidence of active exploitation.

    00000130
    85 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28470: CRITICAL] OpenClaw < 2026.2.2 has an exec approvals allowlist bypass flaw, enabling attackers to run unauthorized commands by injecting command substitution syntax.#cve,CVE-2026-28470,#cybersecurity https://cvefind.com/CVE-2026-28470

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑28470) in OpenClaw versions before 2026.2.2, describing an allowlist bypass that permits attackers to execute unauthorized commands through command substitution.

    0000075
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more