Threat reportVulnerabilityTL-2026-0687
OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass — Five Advisories Hijack Trusted AI Agent Access (incl. CVE-2026-28480)
OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass (TL-2026-0687), also tracked as Five OpenClaw 0-Days, is a high-severity software vulnerability scored CVSS 9.4, first published 2026-06-06. It has no confirmed attribution, affects OpenClaw openclaw (Telegram channel), references 1 CVE (CVE-2026-28480), maps to 10 MITRE ATT&CK techniques (T1059, T1068, T1078), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 9.4/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-0687
- Threat ID
- TL-2026-0687
- Also known as
- Five OpenClaw 0-Days, OpenClaw Allowlist Identity-Resolution Bypass
- Severity
- HIGH
- CVSS
- 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise software, AI/ML platforms, messaging/collaboration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
How OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass works
A recurring authorization-bypass root cause across OpenClaw's channel extensions lets remote attackers defeat DM/command allowlists and hijack trusted AI-agent access. Allowlists were matched against mutable, attacker-controllable identity fields (Telegram/Discord usernames, Matrix display names and bare localparts, caller-ID suffixes) instead of immutable IDs, and in some channels sender policy silently downgraded from allowlist to open. First fixed in the Telegram integration (GHSA-mj5r-hh7j-4gxf / CVE-2026-28480), the same class recurred across five further advisories spanning Matrix, the voice-call extension, Google Chat, Zalouser, Discord and WhatsApp.
OpenClaw is a widely integrated AI-agent platform that connects an autonomous agent to messaging and voice channels. Operators restrict who may drive the agent using per-channel allowlists (e.g. channels.matrix.dm.allowFrom, commands.allowFrom, inboundPolicy: allowlist). A single design anti-pattern — resolving and matching allowlist entries against mutable, sender-controllable identity fields rather than immutable platform IDs — recurred across six OpenClaw channel extensions, producing five public security advisories disclosed in February–March 2026. An AI-driven static-analysis tool, 'agentgg', which generates custom detectors from historical advisories, surfaced the recurring pattern after the initial Telegram fix.
GHSA-mj5r-hh7j-4gxf (CVE-2026-28480, Telegram): The allowlist matched Telegram @usernames instead of immutable numeric sender IDs. Because Telegram usernames can be released and re-registered, an attacker who acquires a username previously held by an allowlisted user is silently treated as authorized. CVSS 4.0 base 6.9; CWE-290 (Authentication Bypass by Spoofing) / CWE-284. Affected openclaw <= 2026.2.13 (clawdbot <= 2026.1.24-3); fixed 2026.2.14. Patch enforces numeric-ID-only entries and rejects @username; 'openclaw doctor --fix' best-effort migrates legacy entries. Reported by Vincent Koc (@vincentkoc).
GHSA-rmxw-jxxx-4cpc (Matrix): The DM allowlist accepted multiple sender-derived candidates beyond full MXIDs — attacker-controlled display names and bare localparts with the homeserver discarded (@alice:evil.example and @alice:trusted.example both reduce to 'alice'). A remote Matrix user can thus impersonate an allowlisted identity across homeservers. Affected >= 2026.1.14-1, < 2026.2.2; fixed 2026.2.2. Patch commit 8f3bfbd1c4fb967a2ddb5b4b9a05784920814bcf. Reported by MegaManSec (Joshua Hughes) / AISLE Research Team.
GHSA-4rj2-gpmh-qq5x (voice-call extension): Two flaws in extensions/voice-call/src/manager.ts inbound allowlist validation — (1) missing/empty 'from' values normalized to empty strings bypassed the allowlist (anonymous/restricted callers reached the agent), and (2) suffix matching accepted any caller whose digits ended with an allowlisted number (allowlist +15550001234 matched +99915550001234). CVSS 9.4 (Critical); CWE-287 (Improper Authentication). Affected <= 2026.2.1; fixed 2026.2.2. Patch commit f8dfd034f5d9235c5485f492a9e4ccc114e97fdb enforces strict equality and rejects missing IDs. Reported by @simecek and @MegaManSec; analysis @stanislavfortaisle.
GHSA-2ch6-x3g4-7759 (Discord / WhatsApp): resolveSenderCandidates() in src/auto-reply/command-auth.ts incorrectly included ctx.From, which is sender-like in DMs but conversation-like in channel/group/thread contexts (Discord channel:<id>, WhatsApp group JIDs). When commands.allowFrom was configured with conversation identifiers, any participant of an allowlisted conversation could execute command-only flows, defeating sender-only authorization. CWE-639 (Authorization Bypass Through User-Controlled Key). Affected <= 2026.2.22-2; fixed 2026.2.23. Patch commit 08e2aa44e78a9c946d97bea62304e6f533b8fa8e. Reported by @jiseoung.
GHSA-63mg-xp9j-jfcm (Google Chat / Zalouser): When a route-level group allowlist was the only configured restriction, sender policy resolution silently downgraded from 'allowlist' to 'open', so any member of an allowlisted Google Chat space or Zalouser group could drive the bot. Affected files extensions/googlechat/src/monitor-access.ts and extensions/zalouser/src/monitor.ts. Affected <= 2026.3.24; fixed 2026.3.28. Patch commit e64a881ae0 ('Channels: preserve routed group policy'). Reported by AntAISecurityLab.
Impact: Successful exploitation grants an attacker the trusted agent's privileges — the ability to issue commands, read conversation context, and trigger any tool/automation the agent is wired to — while in the rename/restart variant simultaneously locking out the legitimate principal. The class is significant because it is an AI-agent supply-chain authorization weakness in a platform whose use is expanding across enterprise messaging. No in-the-wild exploitation has been reported; all six issues are patched and several include public, PoC-level root-cause detail.
MITRE ATT&CK techniques used in TL-2026-0687
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship
Discovery
Persistence
Credential Access
T1212 Exploitation for Credential Access
Resource Development
Defense Evasion
Affected products and versions in OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass
- OpenClaw — openclaw (Telegram channel)
Vulnerable versions: <= 2026.2.13
Fixed in: 2026.2.14 - OpenClaw — clawdbot
Vulnerable versions: <= 2026.1.24-3
Fixed in: 2026.2.14 - OpenClaw — openclaw (Matrix extension)
Vulnerable versions: >= 2026.1.14-1, < 2026.2.2
Fixed in: 2026.2.2 - OpenClaw — openclaw (voice-call extension)
Vulnerable versions: <= 2026.2.1
Fixed in: 2026.2.2 - OpenClaw — openclaw (Discord/WhatsApp command-auth)
Vulnerable versions: <= 2026.2.22-2
Fixed in: 2026.2.23 - OpenClaw — openclaw (Google Chat / Zalouser extensions)
Vulnerable versions: <= 2026.3.24
Fixed in: 2026.3.28
Remediation for OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass
Patches
- openclaw 2026.2.14 (GHSA-mj5r-hh7j-4gxf, commits e3b432e4 / 9e147f00)
- openclaw 2026.2.2 (GHSA-rmxw-jxxx-4cpc commit 8f3bfbd1; GHSA-4rj2-gpmh-qq5x commit f8dfd034)
- openclaw 2026.2.23 (GHSA-2ch6-x3g4-7759 commit 08e2aa44)
- openclaw 2026.3.28 (GHSA-63mg-xp9j-jfcm commit e64a881a)
Immediate actions
- Upgrade OpenClaw to the per-channel fixed versions: Telegram/core >= 2026.2.14, Matrix >= 2026.2.2, voice-call >= 2026.2.2, Discord/WhatsApp command-auth >= 2026.2.23, Google Chat/Zalouser >= 2026.3.28
- Audit every allowlist (channels.*.dm.allowFrom, commands.allowFrom, inboundPolicy/allowFrom) and replace mutable identifiers with immutable IDs
- Run 'openclaw doctor --fix' to migrate legacy Telegram @username allowlist entries to numeric IDs
Workarounds
- Until patched, configure allowlists exclusively with immutable IDs (numeric Telegram IDs, full @user:server MXIDs)
- Disable optional channel extensions (Matrix, voice-call, Google Chat, Zalouser) where not required
- Avoid using conversation/group identifiers in commands.allowFrom; restrict to verified individual sender IDs
Longer-term hardening
- Standardize allowlist matching on immutable, server-issued identifiers (Telegram numeric ID, full Matrix MXID, Discord user snowflake) across all channels
- Add regression tests asserting allowlist rejects display names, bare localparts, caller-ID suffixes, empty senders, and conversation identifiers
- Treat sender-policy 'downgrade to open' as a fail-closed error rather than a silent fallback
- Monitor agent command/tool invocations for anomalous principals after channel-service restarts
CVEs associated with OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass
CVE-2026-28480
Weaknesses (CWE) in OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass
Timeline of OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass
- GHSA-rmxw-jxxx-4cpc (Matrix display-name/localpart bypass) and GHSA-4rj2-gpmh-qq5x (voice-call empty/suffix caller-ID bypass, CVSS 9.4) published; fixed in 2026.2.2.
- GHSA-mj5r-hh7j-4gxf published — Telegram allowlist accepted mutable @usernames; fixed in openclaw 2026.2.14 (commits e3b432e4 / 9e147f00).
- GHSA-2ch6-x3g4-7759 published — Discord/WhatsApp command-auth treated conversation identifiers as senders (CWE-639); fixed in 2026.2.23 (commit 08e2aa44).
- CVE-2026-28480 assigned to the Telegram mutable-username flaw; VulnCheck advisory scores it CVSS 4.0 6.9 (CWE-290).
- GHSA-63mg-xp9j-jfcm published — Google Chat/Zalouser route-level group allowlist silently downgraded to 'open'; fixed in 2026.3.28 (commit e64a881a).
- Cyber Security News and Cybernews report the recurring root cause as 'five OpenClaw 0-days', noting discovery via the agentgg AI static-analysis tool amid expanding enterprise/Microsoft use of the platform.
Sources cited for OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass
- Five OpenClaw 0-Days let Attackers Hijack Trusted AI Agent Access
- GHSA-mj5r-hh7j-4gxf — Telegram allowlist accepted mutable usernames (CVE-2026-28480)
- GHSA-rmxw-jxxx-4cpc — Matrix allowlist bypass via displayName and cross-homeserver localpart matching
- GHSA-4rj2-gpmh-qq5x — Voice-call extension allowlist bypass (empty/suffix caller ID)
- GHSA-2ch6-x3g4-7759 — Discord/WhatsApp command-auth conversation-principal bypass
- GHSA-63mg-xp9j-jfcm — Google Chat/Zalouser sender-policy downgrade to open
- VulnCheck — OpenClaw Identity Spoofing via Mutable Username in Telegram Allowlist Authorization (CVE-2026-28480)
- Researcher easily finds five OpenClaw zero-days just as Microsoft expands its use of platform
Detection coverage for TL-2026-0687
As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0687 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.