2026 CVE Vulnerabilities
70,011 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29606 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al... |
| CVE-2026-28486 | MEDIUM | 5.5 | 0.2% | Mar 5, 2026 | OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during ins... |
| CVE-2026-28485 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control... |
| CVE-2026-28484 | — | — | — | Mar 5, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-28482 | HIGH | 8.4 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF... |
| CVE-2026-28481 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS... |
| CVE-2026-28480 | MEDIUM | 6.9 | 0.2% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching acc... |
| CVE-2026-28479 | CRITICAL | 9.1 | 0.2% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox conf... |
| CVE-2026-28478 | HIGH | 8.7 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b... |
| CVE-2026-28477 | HIGH | 7.1 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f... |
| CVE-2026-28476 | MEDIUM | 5.8 | 0.2% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit exte... |
| CVE-2026-28475 | LOW | 3.7 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attacke... |
| CVE-2026-28474 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display n... |
| CVE-2026-28473 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop... |
| CVE-2026-28472 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allow... |
| CVE-2026-28471 | MEDIUM | 6.3 | 0.2% | Mar 5, 2026 | OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in... |
| CVE-2026-28470 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allo... |
| CVE-2026-28469 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that a... |
| CVE-2026-28468 | HIGH | 7.7 | 0.1% | Mar 5, 2026 | OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in wh... |
| CVE-2026-28467 | HIGH | 8.6 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydr... |
| CVE-2026-28466 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal appro... |
| CVE-2026-28465 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi... |
| CVE-2026-28464 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke... |
| CVE-2026-28463 | MEDIUM | 5.5 | 0.2% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist valida... |
| CVE-2026-28462 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now