CVE-2026-28392

HIGH

OpenClaw <2026.2.14 - Privilege Escalation

Title source: llm
STIX 2.1

Description

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message sender when dmPolicy is set to open (must be configured). Attackers can execute privileged slash commands via direct message to bypass allowlist and access-group restrictions.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
npm/openclaw 0 - 2026.2.14npm
openclaw/openclaw < 2026.2.14
Published Mar 05, 2026
Tracked Since Mar 06, 2026