CVE-2026-28480 Details
Description
OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.
A vulnerability exists in OpenClaw versions prior to 2026.2.14, allowing an authorization bypass in Telegram integrations. The issue arises because the allowlist matching process accepts mutable usernames instead of the required immutable numeric sender IDs. This flaw enables attackers to spoof identities by using recycled usernames to circumvent allowlist restrictions, allowing unauthorized interaction with bots.
Users are advised to update to OpenClaw version 2026.2.14 or later, where this vulnerability has been patched. After updating, run the 'openclaw doctor --fix' command to resolve any remaining '@username' entries in the allowlist to their corresponding numeric IDs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.2.14 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Mar 5, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | New CVE Received | [email protected] |