CVE-2026-41354

LOW

OpenClaw < 2026.4.2 - Insufficient Scope in Zalo Webhook Replay Dedupe Keys

Title source: cna

Description

OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. Attackers can exploit weak deduplication scoping to cause silent message suppression and disrupt bot workflows across chat sessions.

Scores

CVSS v3 3.7
EPSS 0.0004
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-706
Status published
Products (2)
OpenClaw/OpenClaw < 2026.4.2
OpenClaw/OpenClaw 2026.4.2
Published Apr 23, 2026
Tracked Since Apr 24, 2026