PT-2026-49034 · Openclaw · Openclaw
CVE-2026-53830
·
Published
2026-06-12
·
Updated
2026-07-02
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.22
Description
A webhook secret revocation bypass allows callers using outdated Slack and Zalo webhook secrets to remain active after the
secrets.reload function is executed. This creates a stale-secret window that enables attackers to deliver webhook events and potentially use previous credentials after the operator intended to revoke them.Recommendations
Update to version 2026.4.22.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw