CVE-2026-28449

OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound message processing and cause integrity or availability issues.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

25 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : 6.5
Summary
  • (es) Las versiones de OpenClaw anteriores a 2026.2.25 carecen de un estado de reproducción duradero para los eventos de webhook de Nextcloud Talk, lo que permite que las solicitudes de webhook firmadas válidas se reproduzcan sin supresión. Los atacantes pueden capturar y reproducir solicitudes de webhook firmadas previamente válidas para desencadenar el procesamiento duplicado de mensajes entrantes y causar problemas de integridad o disponibilidad.

19 Mar 2026, 19:19

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/d512163d686ad6741783e7119ddb3437f493dbbc - () https://github.com/openclaw/openclaw/commit/d512163d686ad6741783e7119ddb3437f493dbbc - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-r9q5-c7qc-p26w - () https://github.com/openclaw/openclaw/security/advisories/GHSA-r9q5-c7qc-p26w - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-webhook-replay-attack-via-missing-durable-replay-suppression - () https://www.vulncheck.com/advisories/openclaw-webhook-replay-attack-via-missing-durable-replay-suppression - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

19 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 02:16

Updated : 2026-03-25 15:16


NVD link : CVE-2026-28449

Mitre link : CVE-2026-28449

CVE.ORG link : CVE-2026-28449


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-294

Authentication Bypass by Capture-replay