CVE-2026-28469 Details
Description
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.
A webhook routing vulnerability has been identified in OpenClaw versions prior to 2026.2.14, specifically within the Google Chat monitor component. This vulnerability allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Exploitation of this vulnerability takes advantage of first-match request verification semantics, leading to the processing of inbound webhook events under incorrect account contexts and bypassing intended allowlists and session policies.
Users can upgrade to OpenClaw version 2026.2.14 or later to address this vulnerability. For those using the deprecated clawdbot package, it is recommended to migrate to OpenClaw and upgrade to version 2026.2.14 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.2.14 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | New CVE Received | [email protected] |