CVE-2026-28469

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

09 Mar 2026, 20:29

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/61d59a802869177d9cef52204767cd83357ab79e - () https://github.com/openclaw/openclaw/commit/61d59a802869177d9cef52204767cd83357ab79e - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-rq6g-px6m-c248 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-rq6g-px6m-c248 - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-cross-account-policy-context-misrouting-via-shared-webhook-path-ambiguity - () https://www.vulncheck.com/advisories/openclaw-cross-account-policy-context-misrouting-via-shared-webhook-path-ambiguity - Third Party Advisory

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.2.14 contienen una vulnerabilidad de enrutamiento de webhook en el componente de monitor de Google Chat que permite el enrutamiento incorrecto del contexto de políticas entre cuentas cuando múltiples destinos de webhook comparten la misma ruta HTTP. Los atacantes pueden exploit la semántica de verificación de solicitudes de primera coincidencia para procesar eventos de webhook entrantes bajo contextos de cuenta incorrectos, eludiendo las listas de permitidos previstas y las políticas de sesión.

06 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-09 20:29


NVD link : CVE-2026-28469

Mitre link : CVE-2026-28469

CVE.ORG link : CVE-2026-28469


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-639

Authorization Bypass Through User-Controlled Key