CVE-2026-33580: OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication
OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33580?
CVE-2026-33580 has a medium severity rating due to the potential for brute force attacks against weak shared secrets.
How do I fix CVE-2026-33580?
To fix CVE-2026-33580, upgrade OpenClaw to version 2026.3.28 or later to implement proper rate limiting.
What impact does CVE-2026-33580 have on my system?
CVE-2026-33580 allows attackers to perform brute force attacks, potentially compromising shared secret authentication on webhooks.
Which versions of OpenClaw are affected by CVE-2026-33580?
OpenClaw versions prior to 2026.3.28 are affected by CVE-2026-33580.
Is there a workaround for CVE-2026-33580?
There is no known workaround for CVE-2026-33580; upgrading to the latest version is the recommended solution.