CVE-2026-8305

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component bluebubbles Webhook. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 2026.2.12 is sufficient to resolve this issue. The patch is named a6653be0265f1f02b9de46c06f52ea7c81a836e6. The affected component should be upgraded.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

16 May 2026, 03:06

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
References () https://github.com/Dave-gilmore-aus/security-advisories/blob/main/ClawdBot(aka%20OpenClaw)-Auth-Bypass-SSRF - () https://github.com/Dave-gilmore-aus/security-advisories/blob/main/ClawdBot(aka%20OpenClaw)-Auth-Bypass-SSRF - Exploit, Mitigation, Vendor Advisory
References () https://github.com/openclaw/openclaw/ - () https://github.com/openclaw/openclaw/ - Product
References () https://github.com/openclaw/openclaw/commit/a6653be0265f1f02b9de46c06f52ea7c81a836e6 - () https://github.com/openclaw/openclaw/commit/a6653be0265f1f02b9de46c06f52ea7c81a836e6 - Patch
References () https://github.com/openclaw/openclaw/issues/13786 - () https://github.com/openclaw/openclaw/issues/13786 - Exploit, Issue Tracking, Mitigation
References () https://github.com/openclaw/openclaw/pull/13787 - () https://github.com/openclaw/openclaw/pull/13787 - Issue Tracking, Patch
References () https://github.com/openclaw/openclaw/releases/tag/v2026.2.12 - () https://github.com/openclaw/openclaw/releases/tag/v2026.2.12 - Release Notes
References () https://vuldb.com/submit/809371 - () https://vuldb.com/submit/809371 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/362590 - () https://vuldb.com/vuln/362590 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/362590/cti - () https://vuldb.com/vuln/362590/cti - Permissions Required, VDB Entry
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

11 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 18:16

Updated : 2026-05-16 03:06


NVD link : CVE-2026-8305

Mitre link : CVE-2026-8305

CVE.ORG link : CVE-2026-8305


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-287

Improper Authentication