CVE-2026-28474
CRITICALOpenClaw Nextcloud Talk <2026.2.6 - Auth Bypass
Title source: llmDescription
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.
Scores
CVSS v3
9.8
EPSS
0.0004
EPSS Percentile
11.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-863
Status
draft
Timeline
Published
Mar 05, 2026
Tracked Since
Mar 06, 2026