CVE-2026-29613

MEDIUM

OpenClaw <2026.2.12 - Auth Bypass

Title source: llm
STIX 2.1

Description

OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operates behind a reverse proxy, unauthenticated remote attackers can inject arbitrary BlueBubbles message and reaction events by reaching the proxy endpoint.

Scores

CVSS v3 5.9
EPSS 0.0004
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
npm/openclaw 0 - 2026.2.12npm
openclaw/openclaw < 2026.2.12
Published Mar 05, 2026
Tracked Since Mar 06, 2026