2026 CVE Vulnerabilities

70,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28465HIGH7.5OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi...
CVE-2026-28464HIGH7.5OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28463MEDIUM5.5OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist valida...
CVE-2026-28462CRITICAL9.1OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie...
CVE-2026-28459HIGH8.1OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli...
CVE-2026-28458MEDIUM5.4OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed ...
CVE-2026-28457HIGH7.9OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)...
CVE-2026-28456HIGH8.6OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c...
CVE-2026-28454CRITICAL9.8OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowin...
CVE-2026-28453CRITICAL9.8OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal...
CVE-2026-28452MEDIUM6.5OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src...
CVE-2026-28451CRITICAL9.3OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that al...
CVE-2026-28450HIGH8.2OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap...
CVE-2026-28448CRITICAL9.4OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enable...
CVE-2026-28447MEDIUM6.5OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that ...
CVE-2026-28446CRITICAL9.8OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass...
CVE-2026-28395CRITICAL9.1OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extensi...
CVE-2026-28394MEDIUM6.9OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attacke...
CVE-2026-28393CRITICAL9.8OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading...
CVE-2026-28392CRITICAL9.8OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler tha...
CVE-2026-28391CRITICAL9.8OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec req...
CVE-2026-21622CRITICAL9.8Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows...
CVE-2026-29188HIGH8.1File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-29081HIGH8.8Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to...
CVE-2026-29077HIGH7.1Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now