CVE-2026-41362: OpenClaw 2026.2.19 through 2026.3.30 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication
OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitimate events on different accounts by matching eventname and messageid parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.31
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41362?
CVE-2026-41362 is a medium-severity vulnerability due to improper cache isolation affecting authenticated webhook targets.
How do I fix CVE-2026-41362?
To fix CVE-2026-41362, upgrade OpenClaw to version 2026.3.31 or later.
What versions are affected by CVE-2026-41362?
CVE-2026-41362 affects OpenClaw versions from 2026.2.19 up to, but not including, 2026.3.31.
What is the impact of CVE-2026-41362?
The impact of CVE-2026-41362 includes potential unauthorized access to event suppression via webhook replay due to shared authentication.
Is CVE-2026-41362 exploitable remotely?
Yes, CVE-2026-41362 is exploitable remotely if an attacker can access the affected webhook endpoints.