CVE-2026-28448 Details
Description
OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twitch users to trigger agent dispatch. Remote attackers can mention the bot in Twitch chat to bypass access control and invoke the agent pipeline, potentially causing unintended actions or resource exhaustion.
A vulnerability exists in the OpenClaw Twitch plugin, versions 2026.1.29 prior to 2026.2.1, due to improper enforcement of the allowFrom allowlist. When allowedRoles is unset or empty, the plugin defaults to allowing all users, which can be exploited by mentioning the bot in Twitch chat. This bypasses access controls and triggers the agent dispatch pipeline, potentially leading to unintended actions or resource exhaustion.
Users can upgrade to OpenClaw version 2026.2.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | >= 2026.1.29, < 2026.2.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | New CVE Received | [email protected] |