CVE-2026-41402: OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass
OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the same messageId. Attackers can exploit overly broad cache keying to bypass replay protection and deliver duplicate webhook messages to unintended targets.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41402?
CVE-2026-41402 has a high severity rating due to the potential for authenticated attackers to exploit the scope bypass vulnerability.
How do I fix CVE-2026-41402?
To fix CVE-2026-41402, upgrade OpenClaw to version 2026.3.31 or later.
Who is affected by CVE-2026-41402?
CVE-2026-41402 affects users of OpenClaw versions prior to 2026.3.31.
What type of attacks can CVE-2026-41402 enable?
CVE-2026-41402 enables authenticated attackers to replay messages across sibling targets using the same messageId.
Is authentication required to exploit CVE-2026-41402?
Yes, exploitation of CVE-2026-41402 requires authentication to the OpenClaw application.