CVE-2026-45005
OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation
CVSS Score
6.0
EPSS Score
0.0%
EPSS Percentile
13th
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.
| CWE | CWE-672 |
| Vendor | openclaw |
| Product | openclaw |
| Published | May 11, 2026 |
| Last Updated | May 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for openclaw openclaw
Be the first to know when new medium vulnerabilities affecting openclaw openclaw are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low
Affected Versions
OpenClaw / OpenClaw
0 < 2026.4.23
References
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-q8ff-7ffm-m3r9 github.com: https://github.com/openclaw/openclaw/commit/36c4a372a0ad5dca8bfc0d93f7aab9c2f2de66fa vulncheck.com: https://www.vulncheck.com/advisories/openclaw-webhook-route-secret-cache-not-invalidated-after-rotation
Credits
π δΎ―ζ΅·ι£ (@feynman-hou)