PT-2026-23546 · Openclaw · Openclaw
Megamansec
·
Published
2026-02-17
·
Updated
2026-03-07
·
CVE-2026-28471
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.1.14-1 through 2026.2.1
Description
The software contains a flaw where direct message (DM) allowlist matching can be circumvented by precisely matching sender display names and localparts without homeserver verification. This allows remote Matrix users to impersonate permitted identities by utilizing attacker-controlled display names or matching localparts from different homeservers, potentially reaching the routing and agent pipeline. The issue arises because DM allowlist decisions are made by exact-matching entries against sender-derived candidates, including the sender display name and the sender MXID localpart without the homeserver component. If an operator configures Matrix allowlists with display names or bare localparts, a remote Matrix user may be able to impersonate an allowed identity.
Recommendations
Upgrade to OpenClaw version 2026.2.2 or later.
Ensure Matrix allowlists contain only full Matrix user IDs (MXIDs) like
@user:server. Do not use display names or bare localparts.Fix
Authentication Bypass by Spoofing
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw