PT-2026-49034 · Openclaw · Openclaw

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-53830

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2026-53830

Affected Products

Openclaw