# OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass — Five Advisories Hijack Trusted AI Agent Access (incl. CVE-2026-28480)

> A recurring authorization-bypass root cause across OpenClaw's channel extensions lets remote attackers defeat DM/command allowlists and hijack trusted AI-agent access. Allowlists were matched against mutable, attacker-controllable identity fields (Telegram/Discord usernames, Matrix display names and bare localparts, caller-ID suffixes) instead of immutable IDs, and in some channels sender policy silently downgraded from allowlist to open. First fixed in the Telegram integration (GHSA-mj5r-hh7j-4gxf / CVE-2026-28480), the same class recurred across five further advisories spanning Matrix, the voice-call extension, Google Chat, Zalouser, Discord and WhatsApp.

- **Published:** 2026-06-06T00:00:00Z
- **Last reviewed:** 2026-06-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0687
- **ID:** TL-2026-0687
- **Severity:** HIGH (CVSS 9.4)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-28480

## Description

OpenClaw is a widely integrated AI-agent platform that connects an autonomous agent to messaging and voice channels. Operators restrict who may drive the agent using per-channel allowlists (e.g. channels.matrix.dm.allowFrom, commands.allowFrom, inboundPolicy: allowlist). A single design anti-pattern — resolving and matching allowlist entries against mutable, sender-controllable identity fields rather than immutable platform IDs — recurred across six OpenClaw channel extensions, producing five public security advisories disclosed in February–March 2026. An AI-driven static-analysis tool, 'agentgg', which generates custom detectors from historical advisories, surfaced the recurring pattern after the initial Telegram fix.

GHSA-mj5r-hh7j-4gxf (CVE-2026-28480, Telegram): The allowlist matched Telegram @usernames instead of immutable numeric sender IDs. Because Telegram usernames can be released and re-registered, an attacker who acquires a username previously held by an allowlisted user is silently treated as authorized. CVSS 4.0 base 6.9; CWE-290 (Authentication Bypass by Spoofing) / CWE-284. Affected openclaw <= 2026.2.13 (clawdbot <= 2026.1.24-3); fixed 2026.2.14. Patch enforces numeric-ID-only entries and rejects @username; 'openclaw doctor --fix' best-effort migrates legacy entries. Reported by Vincent Koc (@vincentkoc).

GHSA-rmxw-jxxx-4cpc (Matrix): The DM allowlist accepted multiple sender-derived candidates beyond full MXIDs — attacker-controlled display names and bare localparts with the homeserver discarded (@alice:evil.example and @alice:trusted.example both reduce to 'alice'). A remote Matrix user can thus impersonate an allowlisted identity across homeservers. Affected >= 2026.1.14-1, < 2026.2.2; fixed 2026.2.2. Patch commit 8f3bfbd1c4fb967a2ddb5b4b9a05784920814bcf. Reported by MegaManSec (Joshua Hughes) / AISLE Research Team.

GHSA-4rj2-gpmh-qq5x (voice-call extension): Two flaws in extensions/voice-call/src/manager.ts inbound allowlist validation — (1) missing/empty 'from' values normalized to empty strings bypassed the allowlist (anonymous/restricted callers reached the agent), and (2) suffix matching accepted any caller whose digits ended with an allowlisted number (allowlist +15550001234 matched +99915550001234). CVSS 9.4 (Critical); CWE-287 (Improper Authentication). Affected <= 2026.2.1; fixed 2026.2.2. Patch commit f8dfd034f5d9235c5485f492a9e4ccc114e97fdb enforces strict equality and rejects missing IDs. Reported by @simecek and @MegaManSec; analysis @stanislavfortaisle.

GHSA-2ch6-x3g4-7759 (Discord / WhatsApp): resolveSenderCandidates() in src/auto-reply/command-auth.ts incorrectly included ctx.From, which is sender-like in DMs but conversation-like in channel/group/thread contexts (Discord channel:<id>, WhatsApp group JIDs). When commands.allowFrom was configured with conversation identifiers, any participant of an allowlisted conversation could execute command-only flows, defeating sender-only authorization. CWE-639 (Authorization Bypass Through User-Controlled Key). Affected <= 2026.2.22-2; fixed 2026.2.23. Patch commit 08e2aa44e78a9c946d97bea62304e6f533b8fa8e. Reported by @jiseoung.

GHSA-63mg-xp9j-jfcm (Google Chat / Zalouser): When a route-level group allowlist was the only configured restriction, sender policy resolution silently downgraded from 'allowlist' to 'open', so any member of an allowlisted Google Chat space or Zalouser group could drive the bot. Affected files extensions/googlechat/src/monitor-access.ts and extensions/zalouser/src/monitor.ts. Affected <= 2026.3.24; fixed 2026.3.28. Patch commit e64a881ae0 ('Channels: preserve routed group policy'). Reported by AntAISecurityLab.

Impact: Successful exploitation grants an attacker the trusted agent's privileges — the ability to issue commands, read conversation context, and trigger any tool/automation the agent is wired to — while in the rename/restart variant simultaneously locking out the legitimate principal. The class is significant because it is an AI-agent supply-chain authorization weakness in a platform whose use is expanding across enterprise messaging. No in-the-wild exploitation has been reported; all six issues are patched and several include public, PoC-level root-cause detail.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1199 Trusted Relationship
- T1190 Exploit Public-Facing Application
- T1684.001 Impersonation
- T1212 Exploitation for Credential Access
- T1068 Exploitation for Privilege Escalation
- T1098 Account Manipulation
- T1059 Command and Scripting Interpreter
- T1585 Establish Accounts
- T1087 Account Discovery

## Sources

- [Five OpenClaw 0-Days let Attackers Hijack Trusted AI Agent Access](https://cybersecuritynews.com/five-openclaw-0-days/)
- [GHSA-mj5r-hh7j-4gxf — Telegram allowlist accepted mutable usernames (CVE-2026-28480)](https://github.com/openclaw/openclaw/security/advisories/GHSA-mj5r-hh7j-4gxf)
- [GHSA-rmxw-jxxx-4cpc — Matrix allowlist bypass via displayName and cross-homeserver localpart matching](https://github.com/openclaw/openclaw/security/advisories/GHSA-rmxw-jxxx-4cpc)
- [GHSA-4rj2-gpmh-qq5x — Voice-call extension allowlist bypass (empty/suffix caller ID)](https://github.com/openclaw/openclaw/security/advisories/GHSA-4rj2-gpmh-qq5x)
- [GHSA-2ch6-x3g4-7759 — Discord/WhatsApp command-auth conversation-principal bypass](https://github.com/openclaw/openclaw/security/advisories/GHSA-2ch6-x3g4-7759)
- [GHSA-63mg-xp9j-jfcm — Google Chat/Zalouser sender-policy downgrade to open](https://github.com/openclaw/openclaw/security/advisories/GHSA-63mg-xp9j-jfcm)
- [VulnCheck — OpenClaw Identity Spoofing via Mutable Username in Telegram Allowlist Authorization (CVE-2026-28480)](https://www.vulncheck.com/advisories/openclaw-identity-spoofing-via-mutable-username-in-telegram-allowlist-authorization)
- [Researcher easily finds five OpenClaw zero-days just as Microsoft expands its use of platform](https://cybernews.com/security/openclaw-zero-days-research-microsoft/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0687
