PT-2026-23555 · Openclaw+2 · Openclaw+2

Vincent Koc

·

Publicado

2026-02-14

·

Atualizado

2026-06-06

·

CVE-2026-28480

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14 clawdbot versions prior to 2026.1.24-3
Description The Telegram allowlist authorization mechanism incorrectly matched on mutable usernames (@username) instead of immutable numeric sender IDs. This allowed attackers to spoof identity by obtaining recycled usernames, bypassing allowlist restrictions and interacting with bots as unauthorized senders. This poses an identity rebinding and spoofing risk for operators who rely on Telegram allowlists as strict identity controls. The issue was addressed by requiring numeric Telegram sender IDs for allowlist authorization and rejecting usernames. A security audit warning was added to flag legacy configurations containing non-numeric Telegram allowlist entries. The openclaw doctor --fix command now attempts to resolve username allowFrom entries to numeric IDs.
Recommendations Versions prior to 2026.2.14: Update to version 2026.2.14 or later. Versions prior to 2026.1.24-3: Update to version 2026.1.24-3 or later. Run openclaw doctor --fix to resolve any legacy configurations containing non-numeric Telegram allowlist entries.

Correção

Improper Access Control

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-06158
CVE-2026-28480
GHSA-MJ5R-HH7J-4GXF

Produtos afetados

Openclaw
Telegram
Clawdbot