Scope Bypass Vulnerability in OpenClaw Product by OpenClaw Vendor
CVE-2026-41402
2.3LOW
What is CVE-2026-41402?
OpenClaw before version 2026.3.31 features a vulnerability that allows authenticated attackers to exploit a flaw in webhook replay cache deduplication. This flaw enables attackers to bypass replay protections and transmit duplicate webhook messages to unintended targets by leveraging overly broad cache keying. It poses significant risks to data integrity and message delivery across systems.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
