Authentication Bypass in OpenClaw Affecting Feishu Webhook and Card-Action Validation
CVE-2026-44109
9.2CRITICAL
What is CVE-2026-44109?
OpenClaw versions prior to 2026.4.15 are vulnerable to an exploitation issue that permits unauthenticated requests to bypass Feishu webhook and card-action validation. This vulnerability arises due to inadequate encryptKey configuration and empty callback tokens, which allow attackers to circumvent signature verification and replay protection measures. As a result, malicious actors can execute arbitrary commands within the system, posing significant security risks.
Affected Version(s)
OpenClaw 0 < 2026.4.15
OpenClaw 2026.4.15
