Scope Bypass Vulnerability in OpenClaw Product by OpenClaw Vendor
CVE-2026-41402

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41402?

OpenClaw before version 2026.3.31 features a vulnerability that allows authenticated attackers to exploit a flaw in webhook replay cache deduplication. This flaw enables attackers to bypass replay protections and transmit duplicate webhook messages to unintended targets by leveraging overly broad cache keying. It poses significant risks to data integrity and message delivery across systems.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

smaeljaish771
KeenSecurityLab
.