CVE-2026-25474
Last modified
CVE-2026-25474 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployments where the webhook endpoint is reachable by an attacker, this can allow forged Telegram updates (for example spoofing message.from.id). If an attacker can reach the webhook endpoint, they may be able to send forged updates that are processed as if they came from Telegram. Depending on enabled commands/tools and configuration, this could lead to unintended bot actions. Note: Telegram webhook mode is not enabled by default. It is enabled only when `channels.telegram.webhookUrl` is configured. This issue has been fixed in version 2026.2.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.2.1 |
References
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.1Product, Release Notes
- https://github.com/openclaw/openclaw/security/advisories/GHSA-mp5h-m6qj-6292Exploit, Mailing List, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-25474?
How severe is CVE-2026-25474?
How do I fix CVE-2026-25474?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25469Missing Authorization vulnerability in ViaBill for WooCommer…6.5
- CVE-2026-2547A vulnerability was detected in LigeroSmart up to 6.1.26. Th…6.1
- CVE-2026-25470Improper Control of Generation of Code ('Code Injection') vu…10
- CVE-2026-25471Authentication Bypass Using an Alternate Path or Channel vul…8.1
- CVE-2026-25472Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-25473Missing Authorization vulnerability in AA-Team WZone woozone…5.4
- CVE-2026-25475OpenClaw is a personal AI assistant. Prior to version 2026.1…6.5
- CVE-2026-25476OpenEMR is a free and open source electronic health records …7.5
- CVE-2026-25477AFFiNE is an open-source, all-in-one workspace and an operat…6.1
- CVE-2026-25478Litestar is an Asynchronous Server Gateway Interface (ASGI) …6.5
- CVE-2026-25479Litestar is an Asynchronous Server Gateway Interface (ASGI) …6.5
- CVE-2026-2548A flaw has been found in WAYOS FBM-220G 24.10.19. This affec…6.3
Are you affected by CVE-2026-25474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
