PT-2026-26745 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-03-21
·
Updated
2026-03-21
·
CVE-2026-32896
CVSS v3.1
4.8
Medium
| AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
OpenClaw versions prior to 2026.2.21 BlueBubbles webhook handler contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heuristics to send unauthenticated webhook events to the BlueBubbles plugin.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw