ThreadLinqs[verified]@threadlinqsActive Exploitation
OpenClaw allowlist bypass CVE-2026-28480 has been detected 9 times in the wild, indicating active exploitation, but no PoC, exploit code, or patch information is provided.
ThreadLinqs[verified]@threadlinqsActive Exploitation
The threat intel report confirms that CVE-2026-28480, an allowlist bypass that hijacks AI agents, is actively exploited in the wild, evidenced by nine detections and 13 indicators of compromise.
Infoflowcloud@infoflowcloudDisclosure
The tweet discloses CVE‑2026‑28480 for OpenClaw, describing an authorization bypass via mutable usernames in allowlist matching, but provides no patch, exploit, or PoC information.
CVE@CVEnewDisclosure
The text discloses that OpenClaw versions before 2026.2.14 contain an authorization bypass flaw related to mutable usernames in Telegram allowlist matching; no PoC, exploit, or patch is mentioned.
CVEFind.com@CveFindComDisclosure
The tweet announces a critical authorization bypass in OpenClaw pre‑2026.2.14 that enables attackers to spoof identities and interact with bots, but no PoC, exploit code, active exploitation, patch, or debunking is mentioned.