CVE-2026-28485 | OpenClaw up to 2026.2.11 /agent/act missing authentication (GHSA-qpjj-47vm-64pj)
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.2.11. This issue affects some unknown processing of the file /agent/act. The manipulation results in missing authentication.
This vulnerability is identified as CVE-2026-28485. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.