PT-2026-49034 · Openclaw · Openclaw

CVE-2026-53830

·

Published

2026-06-12

·

Updated

2026-07-02

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.22
Description A webhook secret revocation bypass allows callers using outdated Slack and Zalo webhook secrets to remain active after the secrets.reload function is executed. This creates a stale-secret window that enables attackers to deliver webhook events and potentially use previous credentials after the operator intended to revoke them.
Recommendations Update to version 2026.4.22.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53830
GHSA-275C-XPVC-JGFW

Affected Products

Openclaw