Insufficient Scope Vulnerability in OpenClaw Affecting Webhook Functionality
CVE-2026-41354
6.3MEDIUM
What is CVE-2026-41354?
An insufficient scope vulnerability in OpenClaw versions before 2026.4.2 allows unauthorized interactions due to weak deduplication scoping of Zalo webhook replay dedupe keys. This can result in the unintended suppression of legitimate chat messages from different conversations, disrupting bot workflows and leading to a degraded user experience. Attackers may leverage this flaw to manipulate message flows, causing significant operational challenges.
Affected Version(s)
OpenClaw 0 < 2026.4.2
OpenClaw 2026.4.2
