Junglewise Threat Intelligence

CVE-2026-28474: OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowl

CVE-2026-28474 · Severity: critical · CVSS 9.8 · Published 2026-03-05

Technologies: Openclaw. Vendors: Openclaw, npm.

Executive brief

OpenClaw's optional Nextcloud Talk plugin is used to integrate real-time messaging and collaboration features. An attacker with a Nextcloud account can change their display name to impersonate an allowlisted user and bypass restrictions on who can send direct messages or access specific chat rooms, potentially gaining unauthorized access to sensitive conversations.

Technical details

The vulnerability is an authorization bypass (CWE-290) in the Nextcloud Talk allowlist matching logic. The plugin's webhook handler incorrectly validates sender identity by comparing the mutable actor.name (display name) field against allowlists, instead of using the stable actor.id identifier. An attacker can change their Nextcloud display name to match an allowlisted user ID and bypass direct message or room allowlists. The vulnerability is network-accessible via webhook payloads and requires no authentication beyond having a valid Nextcloud account. Fix: upgrade @openclaw/nextcloud-talk to version 2026.2.6 or later, which correctly uses actor.id for allowlist matching.

Affected products

  • OpenClaw Nextcloud Talk <=2026.2.2

Timeline

  • 2026-02-17: disclosed
  • 2026-02-07: patched: First fixed npm release 2026.2.6 published

References

Related threats