PT-2026-27226 · Openclaw · Openclaw

Aristore

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32012

CVSS v3.1

4.8

Medium

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
OpenClaw before 2026.2.25 lacks durable replay state for Nextcloud Talk webhook events, allowing valid signed requests to be replayed. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound processing and cause integrity or availability issues.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-32012

Affected Products

Openclaw