CRITICAL
OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing
Published Mar 5, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.88%
Description
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.
Affected products
-
Affected
- ≥ 0, < 2026.2.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| OpenClaw | Nextcloud-Talk | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
@openclaw/nextcloud-talk
npm
Introduced 0 Fixed 2026.2.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @openclaw/nextcloud-talk | 0 | 2026.2.6 |
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9920 Advisory
- https://github.com/advisories/GHSA-r5h9-vjqc-hq3r Advisory
- https://github.com/openclaw/openclaw/commit/660f87278c9f292061e097441e0b10c20d62b31b
- https://github.com/openclaw/openclaw/commit/6b4b6049b47c3329a7014509594647826669892d patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.3
- https://github.com/openclaw/openclaw/security/advisories/GHSA-r5h9-vjqc-hq3r vendor-advisoryPatchVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-nextcloud-talk-allowlist-bypass-via-actorname-display-name-spoofing third-party-advisoryBroken LinkThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9920 | Advisory | |
| https://github.com/advisories/GHSA-r5h9-vjqc-hq3r | Advisory | |
| https://github.com/openclaw/openclaw/commit/660f87278c9f292061e097441e0b10c20d62b31b | ||
| https://github.com/openclaw/openclaw/commit/6b4b6049b47c3329a7014509594647826669892d | patch | |
| https://github.com/openclaw/openclaw/releases/tag/v2026.2.3 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-r5h9-vjqc-hq3r | vendor-advisoryPatchVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-nextcloud-talk-allowlist-bypass-via-actorname-display-name-spoofing | third-party-advisoryBroken LinkThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 5, 2026
Updated Sep 17, 2026
Reserved Feb 27, 2026
Link CVE-2026-28474
CISA Vulnrichment
Updated Mar 9, 2026
Red Hat
No data
GitHub
Link GHSA-R5H9-VJQC-HQ3R