PT-2026-23521 · Openclaw+1 · Openclaw+1

·

CVE-2026-28392

·

Published

2026-02-18

·

Updated

2026-03-10

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The Slack slash-command handler incorrectly authorizes any direct message sender when the dmPolicy is set to open. This allows attackers to execute privileged slash commands via direct message, bypassing allowlist and access-group restrictions. The issue occurs when Slack DMs are enabled with channels.slack.dm.policy: open (also known as dmPolicy=open). Any Slack user who can send a direct message to the bot could invoke privileged slash commands.
Recommendations Update to version 2026.2.14 or later.

Exploit

Fix

LPE

Improper Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28392
GHSA-V773-R54F-Q32W

Affected Products

Openclaw
Slack