
OpenClaw Nextcloud Talk Plugin Allowlist Bypass Vulnerability (CVE-2026-28474) — Critical Severity
A significant security flaw has been discovered in OpenClaw’s Nextcloud Talk plugin, identified as CVE-2026-28474. This vulnerability could allow unauthorized users to gain access to private direct messages and conference rooms by simply altering their display name. Rated as ‘Critical’…
