CVE-2026-35646

MEDIUM

OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated authentication attempts, enabling attackers to guess weak tokens through rapid successive requests.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation
https://www.vulncheck.com/advisories/openclaw-pre-authentication-rate-limit-bypass-in-webhook-token-validation
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-mf5g-6r6f-ghhm)
https://github.com/openclaw/openclaw/security/advisories/GHSA-mf5g-6r6f-ghhm

Scores

CVSS v3 4.8
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (4)
npm/openclaw 0 - 2026.3.28npm
OpenClaw/OpenClaw < 2026.3.25
openclaw/openclaw < 2026.3.25
OpenClaw/OpenClaw 2026.3.25
Published Apr 09, 2026
Tracked Since Apr 10, 2026