PT-2026-29236 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-13

·

Updated

2026-03-31

·

CVE-2026-34505

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.12
Description The software applies rate limiting only after successful webhook authentication. This allows attackers to bypass rate limits and attempt to brute-force webhook secrets. Repeated authentication requests with invalid secrets do not trigger rate limit responses, enabling systematic secret guessing and subsequent forged webhook submission.
Recommendations Update OpenClaw to version 2026.3.12 or later.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2026-34505
GHSA-5M9R-P9G7-679C
GHSA-CXFR-3QP8-HPMW

Affected Products

Openclaw