πŸ” CVE Alert

CVE-2026-45005

MEDIUM 6.0

OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation

CVSS Score
6.0
EPSS Score
0.0%
EPSS Percentile
13th

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.

CWE CWE-672
Vendor openclaw
Product openclaw
Published May 11, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw

Be the first to know when new medium vulnerabilities affecting openclaw openclaw are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low

Affected Versions

OpenClaw / OpenClaw
0 < 2026.4.23

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-q8ff-7ffm-m3r9 github.com: https://github.com/openclaw/openclaw/commit/36c4a372a0ad5dca8bfc0d93f7aab9c2f2de66fa vulncheck.com: https://www.vulncheck.com/advisories/openclaw-webhook-route-secret-cache-not-invalidated-after-rotation

Credits

πŸ” 侯桷飞 (@feynman-hou)