CVE-2026-28484Patch

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-06)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 203-0503-06
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-051
Patch1
2026-03-062
Disclosure1Patch1
Full discourse3 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 7 Critical vulnerabilties in #OpenClaw #NextCloud talk plugin #CVE-2026-28474 #CVE-2026-28466 #CVE-2026-28391 #CVE-2026-28446 #CVE-2026-28470 #CVE-2026-28472 #CVE-2026-28484 CVSS: 9.3-9.2. Update to 2026.2.6 or later https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-openclaws-nextcloud-talk-plugin-patch #Patch

    Post summary

    The post warns of seven critical vulnerabilities in the OpenClaw NextCloud Talk plugin and recommends updating to version 2026.2.6 or later, which includes a patch.

    02021381
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28484 - Critical OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named ... https://www.thehackerwire.com/vulnerability/CVE-2026-28484/ https://t.co/beev5NX0FF

    Post summary

    The text announces OpenClaw versions prior to 2026.2.15 are vulnerable to an option injection flaw in the git‑hooks/pre‑commit hook, allowing attackers to stage ignored files through malicious naming, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000068
    125 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28484: CRITICAL] Beware of OpenClaw security flaw! Versions before 2026.2.15 have a vulnerability allowing attackers to stage ignored files. Update now to stay protected. #CyberSecurity#cve,CVE-2026-28484,#cybersecurity https://cvefind.com/CVE-2026-28484

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-28484) in OpenClaw and urges users to update to version 2026.2.15, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0000067
    596 followersView on X

Explore more