Improper Restriction of Excessive Authentication Attempts in OpenClaw - #VU125214
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass webhook authentication.
The vulnerability exists due to improper restriction of excessive authentication attempts in the Telegram webhook authentication mechanism when handling repeated webhook secret guesses. A remote attacker can send repeated authentication attempts to bypass webhook authentication.
The issue is exploitable against weak webhook secrets.