CVE-2026-28474Disclosure(openclaw / openclaw)

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-11)
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Mentions · 2026-05-11: 4Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 1Technical Details · 2026-05-11: 303-0503-0603-0705-11
Signal classification3 categories
Disclosure
450.0%
Patch
225.0%
General
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-062
Disclosure1Patch1
2026-03-071
Disclosure1
2026-05-114
Disclosure1General2Patch1
Full discourse8 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 7 Critical vulnerabilties in #OpenClaw #NextCloud talk plugin #CVE-2026-28474 #CVE-2026-28466 #CVE-2026-28391 #CVE-2026-28446 #CVE-2026-28470 #CVE-2026-28472 #CVE-2026-28484 CVSS: 9.3-9.2. Update to 2026.2.6 or later https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-openclaws-nextcloud-talk-plugin-patch #Patch

    Post summary

    The advisory alerts about seven critical CVEs in OpenClaw's NextCloud Talk plugin, lists CVSS scores, and recommends updating to version 2026.2.6 or later.

    02021381
    7.2K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-28474-openclaw-openclaw #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text consists only of a link and tags, providing no substantive information about the CVE.

    0000021
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-28474 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑28474, providing its CVSS score, vector, and severity rating as a critical advisory, but no further exploitation details or mitigation steps are offered.

    0000031
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE: CVE-2026-28474 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable http://actor.name display name field for…

    Post summary

    The advisory identifies a critical vulnerability in OpenClaw's Nextcloud Talk plugin, provides CVSS details, states affected versions, and implies a patch in version 2026.2.6.

    0000054
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-28474 (CVSS 9.8) — openclaw openclaw. CVE: CVE-2026-28474 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The snippet announces the critical CVE-2026-28474, providing its CVSS rating but no additional details such as PoC, exploit tools, active exploitation, or patches.

    0000028
    197 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28474 OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable http://actor.name display name field for allowlist validation, allowing a… https://www.cve.org/CVERecord?id=CVE-2026-28474

    Post summary

    The tweet announces CVE-2026-28474 affecting Nextcloud Talk plugin, noting an allowlist validation flaw based on display name equality matching, but provides no PoC, exploit, or patch details.

    00000137
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28474 - Critical OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable http://actor.name display name field for allowlist validation, allowing attackers to bypass DM... https://www.thehackerwire.com/vulnerability/CVE-2026-28474/ https://t.co/fp2dLV5v8z

    Post summary

    CVE-2026-28474 is a critical flaw in OpenClaw's Nextcloud Talk plugin that allows attackers to bypass allowlist validation via equality matching on the mutable actor name field in versions prior to 2026.2.6.

    0000048
    125 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28474: CRITICAL] Vulnerable versions of OpenClaw's Nextcloud Talk plugin allow attackers to bypass allowlists by changing display names to match an allowlisted user ID, compromising conversation se...#cve,CVE-2026-28474,#cybersecurity https://cvefind.com/CVE-2026-28474

    Post summary

    A critical flaw in OpenClaw's Nextcloud Talk plugin lets attackers bypass allowlists by forging display names, enabling compromise of conversation security.

    0000065
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more