Improper Authentication in OpenClaw - #VU126451
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to reach command dispatch without proper authentication checks.
The vulnerability exists due to improper authentication in Feishu webhook mode and card-action lifecycle validation when handling webhook requests or malformed card-action callbacks. A remote attacker can send a specially crafted request to reach command dispatch without proper authentication checks.
Exploitation is possible in deployments using Feishu webhook mode without a configured encryptKey, or when malformed card-action callbacks with blank callback tokens are processed.