vincentkoc

1 exploit Active since Mar 2026
CVE-2026-28469 WRITEUP HIGH WRITEUP
OpenClaw < 2026.2.14 - Authorization Bypass via Google Chat Webhook Path Ambiguity
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.
CVSS 7.5