LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-28454

CVE-2026-28454 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 5, 2026

OpenClaw - Authentication Bypass

Published: March 5, 2026Updated: March 5, 2026Remote Exploitable

Overview

OpenClaw < 2026.2.2 contains a broken authentication caused by failure to validate webhook secrets in Telegram webhook mode, letting remote attackers spoof Telegram updates and execute privileged bot commands, exploit requires Telegram webhook mode enabled.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 1.9%(Probability of exploitation in next 30 days)

Impact

Remote attackers can bypass sender allowlists and execute privileged bot commands, potentially compromising bot control.

Mitigation

Update to version 2026.2.2 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

šŸ”“ CVE-2026-28454 - Critical (9.8) OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the webhook endpoint that trust attacker-controlled JSON payloads. Remote attackers can... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-28454/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

šŸ”“ CVE-2026-28454 - Critical (9.8) OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the webhook endpoint that trust attacker-controlled JSON payloads. Remote attackers can... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-28454/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-28454
Severity
Critical
CVSS Score
9.8
Type
broken_authentication
Status
new
EPSS
1.9%
Social Posts
2

CWE

  • CWE-345

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1.9%Probability of exploitation in the next 30 days