PT-2026-39703 · Openclaw · Openclaw

Davidgilmore

·

Published

2026-05-11

·

Updated

2026-05-16

·

CVE-2026-8305

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.12
Description An improper authentication issue exists in the bluebubbles Webhook component within the handleBlueBubblesWebhookRequest() function of the extensions/bluebubbles/src/monitor.ts file. This flaw allows a remote attacker to perform a manipulation that bypasses authentication.
Recommendations Upgrade to version 2026.2.12. As a temporary workaround, restrict access to the handleBlueBubblesWebhookRequest() function until the update is applied.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-8305

Affected Products

Openclaw