PT-2026-38242 · Openclaw · Openclaw

Dhyabi2

·

Published

2026-04-17

·

Updated

2026-05-14

·

CVE-2026-44109

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.15
Description An authentication bypass exists in the Feishu webhook and card-action validation. When the encryptKey configuration is missing or callback tokens are blank, the system fails open rather than rejecting requests. This allows unauthenticated requests to reach command dispatch by bypassing signature verification and replay protection, which can lead to the execution of arbitrary commands.
Recommendations Update to version 2026.4.15 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-44109
GHSA-CJG8-85GJ-V9Q2
GHSA-XH72-V6V9-MWHC

Affected Products

Openclaw