Insufficient Scope Vulnerability in OpenClaw Affecting Webhook Functionality
CVE-2026-41354

6.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
23 April 2026

What is CVE-2026-41354?

An insufficient scope vulnerability in OpenClaw versions before 2026.4.2 allows unauthorized interactions due to weak deduplication scoping of Zalo webhook replay dedupe keys. This can result in the unintended suppression of legitimate chat messages from different conversations, disrupting bot workflows and leading to a degraded user experience. Attackers may leverage this flaw to manipulate message flows, causing significant operational challenges.

Affected Version(s)

OpenClaw 0 < 2026.4.2

OpenClaw 2026.4.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steven Siegfried (@D0ub1e-D)
.