CVE-2026-28480
OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.
Vendor
Product
CWE
Yayın Tarihi
2026-03-05 22:16:22
Güncelleme
2026-03-17 17:49:51
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/openclaw/openclaw/commit/9e147f00b48e63e7be6964e0e2a97f2980854128
https://github.com/openclaw/openclaw/commit/e3b432e481a96b8fd41b91273818e514074e05c3
https://github.com/openclaw/openclaw/security/advisories/GHSA-mj5r-hh7j-4gxf
https://www.vulncheck.com/advisories/openclaw-identity-spoofing-via-mutable-username-in-telegram-allowlist-authorization