CVE-2026-28471

Source
https://cve.org/CVERecord?id=CVE-2026-28471
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28471.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-28471
Aliases
Published
2026-03-05T22:16:20.817Z
Modified
2026-03-14T15:05:55.460466Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users can impersonate allowed identities by using attacker-controlled display names or matching localparts from different homeservers to reach the routing and agent pipeline.

References

Affected packages

Git / github.com/openclaw/openclaw

Affected ranges

Type
GIT
Repo
https://github.com/openclaw/openclaw
Events
Database specific
{
    "versions": [
        {
            "introduced": "2026.1.14-1"
        },
        {
            "fixed": "2026.2.2"
        }
    ]
}

Affected versions

v2026.*
v2026.1.14-1
v2026.1.15
v2026.1.16-2
v2026.1.20
v2026.1.21
v2026.1.22
v2026.1.23
v2026.1.24
v2026.1.24-1
v2026.1.29
v2026.1.30
v2026.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28471.json"