Back

CRITICAL

OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing

Published Mar 5, 2026

Description

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Mar 5, 2026
Updated Sep 17, 2026
Reserved Feb 27, 2026

CISA Vulnrichment

Updated Mar 9, 2026

NVD

Status Analyzed
Modified Sep 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Mar 5, 2026
Updated Sep 17, 2026