PT-2026-29236 · Openclaw · Openclaw

·

CVE-2026-34505

·

Publicado

2026-03-13

·

Atualizado

2026-03-31

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.12
Description The software applies rate limiting only after successful webhook authentication. This allows attackers to bypass rate limits and attempt to brute-force webhook secrets. Repeated authentication requests with invalid secrets do not trigger rate limit responses, enabling systematic secret guessing and subsequent forged webhook submission.
Recommendations Update OpenClaw to version 2026.3.12 or later.

Exploit

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34505
GHSA-5M9R-P9G7-679C
GHSA-CXFR-3QP8-HPMW

Produtos afetados

Openclaw