
[CVE-2026-28473: CRITICAL] Critical security alert: OpenClaw (pre-2026.2.2) has an authorization bypass flaw allowing clients to approve/deny exec approval requests with operator.write permission via the /ap...#cve,CVE-2026-28473,#cybersecurity https://cvefind.com/CVE-2026-28473
Post summary
The post announces a critical authorization bypass vulnerability (CVE‑2026‑28473) in OpenClaw pre‑2026.2.2, detailing that clients with operator.write rights can approve or deny exec approval requests through a specific endpoint.



