Missing Authentication for Critical Function in OpenClaw - CVE-2026-29613
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary inbound BlueBubbles message and reaction events.
The vulnerability exists due to missing authentication for the BlueBubbles webhook handler when handling webhook requests through a reverse proxy. A remote attacker can send a specially crafted HTTP POST request to inject arbitrary inbound BlueBubbles message and reaction events.
Only deployments with the optional BlueBubbles channel plugin enabled and the BlueBubbles webhook endpoint exposed through a reverse proxy are affected.