PT-2026-23521 · Slack+1 · Slack+1

Christos

·

Published

2026-02-18

·

Updated

2026-03-10

·

CVE-2026-28392

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The Slack slash-command handler incorrectly authorizes any direct message sender when the dmPolicy is set to open. This allows attackers to execute privileged slash commands via direct message, bypassing allowlist and access-group restrictions. The issue occurs when Slack DMs are enabled with channels.slack.dm.policy: open (also known as dmPolicy=open). Any Slack user who can send a direct message to the bot could invoke privileged slash commands.
Recommendations Update to version 2026.2.14 or later.

Fix

LPE

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-28392
GHSA-V773-R54F-Q32W

Affected Products

Openclaw
Slack