---
id: CVE-2026-28474
title: >-
  OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality
  matching on the mutable actor.name display name field for allowlist
  validation, allowing attackers to bypass DM and room allowlists
summary: >-
  OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality
  matching on the mutable actor.name display name field for allowlist
  validation, allowing attackers to bypass DM and room allowlists. An attacker
  can change their…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: openclaw
product: openclaw
affected:
  - openclaw < 2026.2.6
patched:
  - openclaw 2026.2.6
published: '2026-03-05'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:16:40.903'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28474'
references:
  - url: >-
      https://github.com/openclaw/openclaw/commit/6b4b6049b47c3329a7014509594647826669892d
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-r5h9-vjqc-hq3r
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-nextcloud-talk-allowlist-bypass-via-actorname-display-name-spoofing
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-03-09T18:07:43.724179Z'
epss: 0.00482
epssPercentile: 0.4074
ingestedAt: '2026-09-17T18:25:15.967Z'
---

## Overview

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.

## Affected

- `openclaw < 2026.2.6`

## Remediation

Upgrade past the affected range:

- `openclaw 2026.2.6`
