OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.
References
Configurations
History
No history.
Information
Published : 2026-03-31 15:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-33580
Mitre link : CVE-2026-33580
CVE.ORG link : CVE-2026-33580
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
