Threat reportVulnerabilityTL-2026-0687

OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass — Five Advisories Hijack Trusted AI Agent Access (incl. CVE-2026-28480)

highPATCHED

OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass (TL-2026-0687), also tracked as Five OpenClaw 0-Days, is a high-severity software vulnerability scored CVSS 9.4, first published 2026-06-06. It has no confirmed attribution, affects OpenClaw openclaw (Telegram channel), references 1 CVE (CVE-2026-28480), maps to 10 MITRE ATT&CK techniques (T1059, T1068, T1078), and is covered by 9 detection rules and 14 indicators of compromise.

CVSS
9.4/10High
CVEs
1Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-0687

Threat ID
TL-2026-0687
Also known as
Five OpenClaw 0-Days, OpenClaw Allowlist Identity-Resolution Bypass
Severity
HIGH
CVSS
9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, enterprise software, AI/ML platforms, messaging/collaboration
Target regions
Global
Detection rules
9
Indicators of compromise
14

How OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass works

A recurring authorization-bypass root cause across OpenClaw's channel extensions lets remote attackers defeat DM/command allowlists and hijack trusted AI-agent access. Allowlists were matched against mutable, attacker-controllable identity fields (Telegram/Discord usernames, Matrix display names and bare localparts, caller-ID suffixes) instead of immutable IDs, and in some channels sender policy silently downgraded from allowlist to open. First fixed in the Telegram integration (GHSA-mj5r-hh7j-4gxf / CVE-2026-28480), the same class recurred across five further advisories spanning Matrix, the voice-call extension, Google Chat, Zalouser, Discord and WhatsApp.

OpenClaw is a widely integrated AI-agent platform that connects an autonomous agent to messaging and voice channels. Operators restrict who may drive the agent using per-channel allowlists (e.g. channels.matrix.dm.allowFrom, commands.allowFrom, inboundPolicy: allowlist). A single design anti-pattern — resolving and matching allowlist entries against mutable, sender-controllable identity fields rather than immutable platform IDs — recurred across six OpenClaw channel extensions, producing five public security advisories disclosed in February–March 2026. An AI-driven static-analysis tool, 'agentgg', which generates custom detectors from historical advisories, surfaced the recurring pattern after the initial Telegram fix.

GHSA-mj5r-hh7j-4gxf (CVE-2026-28480, Telegram): The allowlist matched Telegram @usernames instead of immutable numeric sender IDs. Because Telegram usernames can be released and re-registered, an attacker who acquires a username previously held by an allowlisted user is silently treated as authorized. CVSS 4.0 base 6.9; CWE-290 (Authentication Bypass by Spoofing) / CWE-284. Affected openclaw <= 2026.2.13 (clawdbot <= 2026.1.24-3); fixed 2026.2.14. Patch enforces numeric-ID-only entries and rejects @username; 'openclaw doctor --fix' best-effort migrates legacy entries. Reported by Vincent Koc (@vincentkoc).

GHSA-rmxw-jxxx-4cpc (Matrix): The DM allowlist accepted multiple sender-derived candidates beyond full MXIDs — attacker-controlled display names and bare localparts with the homeserver discarded (@alice:evil.example and @alice:trusted.example both reduce to 'alice'). A remote Matrix user can thus impersonate an allowlisted identity across homeservers. Affected >= 2026.1.14-1, < 2026.2.2; fixed 2026.2.2. Patch commit 8f3bfbd1c4fb967a2ddb5b4b9a05784920814bcf. Reported by MegaManSec (Joshua Hughes) / AISLE Research Team.

GHSA-4rj2-gpmh-qq5x (voice-call extension): Two flaws in extensions/voice-call/src/manager.ts inbound allowlist validation — (1) missing/empty 'from' values normalized to empty strings bypassed the allowlist (anonymous/restricted callers reached the agent), and (2) suffix matching accepted any caller whose digits ended with an allowlisted number (allowlist +15550001234 matched +99915550001234). CVSS 9.4 (Critical); CWE-287 (Improper Authentication). Affected <= 2026.2.1; fixed 2026.2.2. Patch commit f8dfd034f5d9235c5485f492a9e4ccc114e97fdb enforces strict equality and rejects missing IDs. Reported by @simecek and @MegaManSec; analysis @stanislavfortaisle.

GHSA-2ch6-x3g4-7759 (Discord / WhatsApp): resolveSenderCandidates() in src/auto-reply/command-auth.ts incorrectly included ctx.From, which is sender-like in DMs but conversation-like in channel/group/thread contexts (Discord channel:<id>, WhatsApp group JIDs). When commands.allowFrom was configured with conversation identifiers, any participant of an allowlisted conversation could execute command-only flows, defeating sender-only authorization. CWE-639 (Authorization Bypass Through User-Controlled Key). Affected <= 2026.2.22-2; fixed 2026.2.23. Patch commit 08e2aa44e78a9c946d97bea62304e6f533b8fa8e. Reported by @jiseoung.

GHSA-63mg-xp9j-jfcm (Google Chat / Zalouser): When a route-level group allowlist was the only configured restriction, sender policy resolution silently downgraded from 'allowlist' to 'open', so any member of an allowlisted Google Chat space or Zalouser group could drive the bot. Affected files extensions/googlechat/src/monitor-access.ts and extensions/zalouser/src/monitor.ts. Affected <= 2026.3.24; fixed 2026.3.28. Patch commit e64a881ae0 ('Channels: preserve routed group policy'). Reported by AntAISecurityLab.

Impact: Successful exploitation grants an attacker the trusted agent's privileges — the ability to issue commands, read conversation context, and trigger any tool/automation the agent is wired to — while in the rename/restart variant simultaneously locking out the legitimate principal. The class is significant because it is an AI-agent supply-chain authorization weakness in a platform whose use is expanding across enterprise messaging. No in-the-wild exploitation has been reported; all six issues are patched and several include public, PoC-level root-cause detail.

MITRE ATT&CK techniques used in TL-2026-0687

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

Discovery

T1087 Account Discovery

Persistence

T1098 Account Manipulation

Credential Access

T1212 Exploitation for Credential Access

Resource Development

T1585 Establish Accounts

Defense Evasion

T1684.001 Impersonation

Affected products and versions in OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass

  • OpenClaw — openclaw (Telegram channel)
    Vulnerable versions: <= 2026.2.13
    Fixed in: 2026.2.14
  • OpenClaw — clawdbot
    Vulnerable versions: <= 2026.1.24-3
    Fixed in: 2026.2.14
  • OpenClaw — openclaw (Matrix extension)
    Vulnerable versions: >= 2026.1.14-1, < 2026.2.2
    Fixed in: 2026.2.2
  • OpenClaw — openclaw (voice-call extension)
    Vulnerable versions: <= 2026.2.1
    Fixed in: 2026.2.2
  • OpenClaw — openclaw (Discord/WhatsApp command-auth)
    Vulnerable versions: <= 2026.2.22-2
    Fixed in: 2026.2.23
  • OpenClaw — openclaw (Google Chat / Zalouser extensions)
    Vulnerable versions: <= 2026.3.24
    Fixed in: 2026.3.28

Remediation for OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass

Patches

  • openclaw 2026.2.14 (GHSA-mj5r-hh7j-4gxf, commits e3b432e4 / 9e147f00)
  • openclaw 2026.2.2 (GHSA-rmxw-jxxx-4cpc commit 8f3bfbd1; GHSA-4rj2-gpmh-qq5x commit f8dfd034)
  • openclaw 2026.2.23 (GHSA-2ch6-x3g4-7759 commit 08e2aa44)
  • openclaw 2026.3.28 (GHSA-63mg-xp9j-jfcm commit e64a881a)

Immediate actions

  • Upgrade OpenClaw to the per-channel fixed versions: Telegram/core >= 2026.2.14, Matrix >= 2026.2.2, voice-call >= 2026.2.2, Discord/WhatsApp command-auth >= 2026.2.23, Google Chat/Zalouser >= 2026.3.28
  • Audit every allowlist (channels.*.dm.allowFrom, commands.allowFrom, inboundPolicy/allowFrom) and replace mutable identifiers with immutable IDs
  • Run 'openclaw doctor --fix' to migrate legacy Telegram @username allowlist entries to numeric IDs

Workarounds

  • Until patched, configure allowlists exclusively with immutable IDs (numeric Telegram IDs, full @user:server MXIDs)
  • Disable optional channel extensions (Matrix, voice-call, Google Chat, Zalouser) where not required
  • Avoid using conversation/group identifiers in commands.allowFrom; restrict to verified individual sender IDs

Longer-term hardening

  • Standardize allowlist matching on immutable, server-issued identifiers (Telegram numeric ID, full Matrix MXID, Discord user snowflake) across all channels
  • Add regression tests asserting allowlist rejects display names, bare localparts, caller-ID suffixes, empty senders, and conversation identifiers
  • Treat sender-policy 'downgrade to open' as a fail-closed error rather than a silent fallback
  • Monitor agent command/tool invocations for anomalous principals after channel-service restarts

CVEs associated with OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass

CVE-2026-28480

Weaknesses (CWE) in OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass

CWE-290, CWE-284, CWE-287, CWE-639

Timeline of OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass

  • GHSA-rmxw-jxxx-4cpc (Matrix display-name/localpart bypass) and GHSA-4rj2-gpmh-qq5x (voice-call empty/suffix caller-ID bypass, CVSS 9.4) published; fixed in 2026.2.2.
  • GHSA-mj5r-hh7j-4gxf published — Telegram allowlist accepted mutable @usernames; fixed in openclaw 2026.2.14 (commits e3b432e4 / 9e147f00).
  • GHSA-2ch6-x3g4-7759 published — Discord/WhatsApp command-auth treated conversation identifiers as senders (CWE-639); fixed in 2026.2.23 (commit 08e2aa44).
  • CVE-2026-28480 assigned to the Telegram mutable-username flaw; VulnCheck advisory scores it CVSS 4.0 6.9 (CWE-290).
  • GHSA-63mg-xp9j-jfcm published — Google Chat/Zalouser route-level group allowlist silently downgraded to 'open'; fixed in 2026.3.28 (commit e64a881a).
  • Cyber Security News and Cybernews report the recurring root cause as 'five OpenClaw 0-days', noting discovery via the agentgg AI static-analysis tool amid expanding enterprise/Microsoft use of the platform.

Sources cited for OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass

Detection coverage for TL-2026-0687

As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0687 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats