OpenClaw Nextcloud Talk Plugin Allowlist Bypass Vulnerability

Vulnerability

A vulnerability exists in OpenClaw's Nextcloud Talk plugin, specifically in versions through 2026.2.2. The issue arises because the plugin accepts equality matching on the mutable display name field for allowlist validation. This flaw allows attackers to spoof their Nextcloud display name to match that of an allowlisted user, thereby bypassing direct message and room allowlists. As a result, unauthorized access to restricted conversations can be gained.

Impact

Exploitation of this vulnerability allows for unauthorized access to conversations by bypassing allowlists.

Reproduction

To reproduce this vulnerability, first ensure that the Nextcloud Talk plugin is installed and active. Then, set up a direct message or room with an allowlist that includes specific user IDs. An attacker can then change their display name to match one of the allowlisted IDs. When they attempt to join the conversation, the plugin will incorrectly validate their access based on the spoofed name, allowing them to bypass restrictions and access the conversation.

Remediation

Users can upgrade the Nextcloud Talk plugin to version 2026.2.6 or later to address this vulnerability.

Added: Mar 5, 2026, 10:30 PM
Updated: Mar 5, 2026, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.3
remediation
0.0
relevance
3.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.