CVE-2026-45005

MEDIUM

OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-q8ff-7ffm-m3r9)
https://github.com/openclaw/openclaw/security/advisories/GHSA-q8ff-7ffm-m3r9
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation
https://www.vulncheck.com/advisories/openclaw-webhook-route-secret-cache-not-invalidated-after-rotation

Scores

CVSS v3 6.0
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-672
Status published
Products (4)
npm/openclaw 0 - 2026.4.23npm
OpenClaw/OpenClaw < 2026.4.23
openclaw/openclaw < 2026.4.23
OpenClaw/OpenClaw 2026.4.23
Published May 11, 2026
Tracked Since May 11, 2026