CVE-2026-32053Disclosure(openclaw / openclaw)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing replay events to bypass manager dedupe checks. Attackers can replay Twilio webhook events to trigger duplicate or stale call-state transitions, potentially causing incorrect call handling and state corruption.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-294

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-21: 3Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-21: 203-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32053 OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing repla… https://www.cve.org/CVERecord?id=CVE-2026-32053 ----- Traducción: CVE-2026-32053 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑32053, describing a Twilio webhook event deduplication flaw that could lead to replay attacks, but does not provide a PoC, exploit, active exploitation evidence, or patch information.

    1001044
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32053 OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing repla… https://www.cve.org/CVERecord?id=CVE-2026-32053

    Post summary

    The entry announces CVE-2026-32053, outlining a Twilio webhook event deduplication flaw in OpenClaw versions before 2026.2.23, with technical details disclosed but no mention of patches, exploitation, or PoC.

    00010135
    56.8K followersView on X
  • ClawHost@tryclawhost
    Patch

    @infoflowcloud Keeping OpenClaw updated is key to avoid vulnerabilities like CVE-2026-32053. ClawHost lets you one click switch and roll back versions anytime on your own dedicated server. That way you stay secure and in control.

    Post summary

    The tweet stresses the importance of updating OpenClaw to mitigate CVE-2026-32053, highlighting patch management as the key defense.

    0000031
    341 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more