CVE-2026-28473Disclosure(openclaw / openclaw)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests by sending the /approve chat command. The /approve command path invokes exec.approval.resolve through an internal privileged gateway client, bypassing the operator.approvals permission check that protects direct RPC calls.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0503-0603-07
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-062
Disclosure2
2026-03-071
Disclosure1
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28473: CRITICAL] Critical security alert: OpenClaw (pre-2026.2.2) has an authorization bypass flaw allowing clients to approve/deny exec approval requests with operator.write permission via the /ap...#cve,CVE-2026-28473,#cybersecurity https://cvefind.com/CVE-2026-28473

    Post summary

    The post announces a critical authorization bypass vulnerability (CVE‑2026‑28473) in OpenClaw pre‑2026.2.2, detailing that clients with operator.write rights can approve or deny exec approval requests through a specific endpoint.

    0000184
    596 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28473 OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests b… https://www.cve.org/CVERecord?id=CVE-2026-28473

    Post summary

    The statement reports an authorization bypass in OpenClaw 2026.2.2 and earlier where users with operator.write scope can improperly approve or deny execution requests.

    00000139
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-28473 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28473-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28473 #openclaw #

    Post summary

    The notice signals the existence of CVE-2026-28473 and provides a link to an advisory page, but offers no technical details, exploit code, or evidence of active exploitation.

    0000084
    3.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28473 - Critical OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests by sending the /approv... https://www.thehackerwire.com/vulnerability/CVE-2026-28473/ https://t.co/bQhRXwr5rN

    Post summary

    The tweet announces CVE‑2026‑28473 as an authorization bypass in OpenClaw, notes that versions before 2026.2.2 are affected, and implicitly recommends upgrading, but provides no PoC, exploit code, or evidence of active exploitation.

    0000079
    125 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more