Improper Restriction of Excessive Authentication Attempts in OpenClaw - #VU125214

 

Improper Restriction of Excessive Authentication Attempts in OpenClaw - #VU125214

Published: April 8, 2026


Vulnerability identifier: #VU125214
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass webhook authentication.

The vulnerability exists due to improper restriction of excessive authentication attempts in the Telegram webhook authentication mechanism when handling repeated webhook secret guesses. A remote attacker can send repeated authentication attempts to bypass webhook authentication.

The issue is exploitable against weak webhook secrets.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.


External References

Related Security Bulletins