Improper access control in OpenClaw - CVE-2026-41362
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in the Zalo webhook replay-dedupe cache when handling authenticated webhook events in multi-account gateway deployments. A remote user can send a replay on one authenticated webhook path to suppress a legitimate event on another account to cause a denial of service.
This issue affects multi-account deployments where authenticated webhook targets share the same gateway, and it does not provide cross-account authentication or data access.