CVE-2026-28454 | OpenClaw up to 2026.2.1 Webhook Endpoint ID data authenticity (GHSA-fhvm-j76f-qmjv)
A vulnerability identified as critical has been detected in OpenClaw up to 2026.2.1. This affects an unknown function of the component Webhook Endpoint. The manipulation of the argument ID leads to insufficient verification of data authenticity.
This vulnerability is traded as CVE-2026-28454. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.