Improper access control in OpenClaw - #VU132774

 

Improper access control in OpenClaw - #VU132774

Published: May 29, 2026


Vulnerability identifier: #VU132774
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to continue delivering webhook events after secret rotation.

The vulnerability exists due to improper access control in Slack and Zalo webhook secret validation when processing webhook requests after secrets.reload. A remote user can send requests using a previously valid webhook secret to continue delivering webhook events after secret rotation.

Only configurations with the affected feature enabled and reachable are vulnerable, and exploitation is limited to the stale-secret window after secret reload.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.22

External References

Related Security Bulletins