2026 CVE Vulnerabilities

70,011 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29606MEDIUM6.5OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al...
CVE-2026-28486MEDIUM5.5OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during ins...
CVE-2026-28485HIGH7.8OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control...
CVE-2026-28484——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-28482HIGH8.4OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF...
CVE-2026-28481HIGH7.5OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS...
CVE-2026-28480MEDIUM6.9OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching acc...
CVE-2026-28479CRITICAL9.1OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox conf...
CVE-2026-28478HIGH8.7OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b...
CVE-2026-28477HIGH7.1OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f...
CVE-2026-28476MEDIUM5.8OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit exte...
CVE-2026-28475LOW3.7OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28474CRITICAL9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display n...
CVE-2026-28473HIGH8.1OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop...
CVE-2026-28472CRITICAL9.8OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allow...
CVE-2026-28471MEDIUM6.3OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in...
CVE-2026-28470CRITICAL9.8OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allo...
CVE-2026-28469HIGH8.2OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that a...
CVE-2026-28468HIGH7.7OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in wh...
CVE-2026-28467HIGH8.6OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydr...
CVE-2026-28466CRITICAL9.9OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal appro...
CVE-2026-28465HIGH7.5OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi...
CVE-2026-28464HIGH7.5OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28463MEDIUM5.5OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist valida...
CVE-2026-28462CRITICAL9.1OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now