CVE-2026-28472Patch(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without providing device identity or pairing by exploiting the presence check instead of validation, potentially gaining operator access in vulnerable deployments.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-06: 3Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 103-0503-0603-07
Signal classification3 categories
Patch
240.0%
Disclosure
240.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-051
Patch1
2026-03-063
Disclosure1General1Patch1
2026-03-071
Disclosure1
Full discourse5 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 7 Critical vulnerabilties in #OpenClaw #NextCloud talk plugin #CVE-2026-28474 #CVE-2026-28466 #CVE-2026-28391 #CVE-2026-28446 #CVE-2026-28470 #CVE-2026-28472 #CVE-2026-28484 CVSS: 9.3-9.2. Update to 2026.2.6 or later https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-openclaws-nextcloud-talk-plugin-patch #Patch

    Post summary

    The advisory announces seven critical CVEs in the OpenClaw NextCloud talk plugin, provides CVSS scores, and directs users to update to version 2026.2.6 or later for a patch.

    02021381
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28472 OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when http://auth.to… https://www.cve.org/CVERecord?id=CVE-2026-28472

    Post summary

    OpenClaw versions before 2026.2.2 have a WebSocket handshake vulnerability that bypasses device identity checks, as noted in CVE‑2026‑28472. No PoC, exploit, or patch details are provided, and there is no evidence of active exploitation.

    00000153
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-28472 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28472-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28472 #openclaw #

    Post summary

    The tweet posts a CVE alert for OpenClaw with a link to further information but provides no technical or exploit details.

    0000091
    3.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28472 - Critical OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but no... https://www.thehackerwire.com/vulnerability/CVE-2026-28472/ https://t.co/ZHmbjrkjMa

    Post summary

    The tweet announces a critical CVE affecting OpenClaw before version 2026.2.2, describing a WebSocket handshake flaw that bypasses identity checks, and provides a link to external details.

    0000066
    125 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28472: CRITICAL] Vulnerability in pre-2026.2.2 OpenClaw allows gateway access without proper validation, risking operator access. Upgrade to latest version to secure against exploitation.#cve,CVE-2026-28472,#cybersecurity https://cvefind.com/CVE-2026-28472

    Post summary

    The post highlights CVE‑2026‑28472, describing unauthorized gateway access without proper validation, and recommends upgrading OpenClaw to the latest version for remediation.

    0000081
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more