CVE-2026-28474 | OpenClaw up to 2026.2.5 nextcloud-talk authorization (GHSA-r5h9-vjqc-hq3r)
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.2.5. The impacted element is an unknown function of the component nextcloud-talk. Such manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-28474. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.