CVE-2026-32974Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inject forged Feishu events and trigger downstream tool execution by reaching the webhook endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-29: 3Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-29: 303-29
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32974: HIGH] Critical authentication bypass vulnerability discovered in OpenClaw before 2026.3.12. Attackers can inject forged Feishu events, triggering downstream tool execution. Upgrade now!#cve,CVE-2026-32974,#cybersecurity https://cvefind.com/CVE-2026-32974

    Post summary

    The post announces a critical authentication bypass in OpenClaw and urges users to upgrade to mitigate the risk.

    1000065
    617 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32974 OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowin… https://www.cve.org/CVERecord?id=CVE-2026-32974

    Post summary

    The entry lists CVE‑2026‑32974 as an authentication bypass issue in Feishu webhooks, but offers no code, exploit, or patch information.

    0000070
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32974 - High OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged ev... https://www.thehackerwire.com/vulnerability/CVE-2026-32974/ https://t.co/2MuXczbAzd

    Post summary

    The announcement details a high‑severity authentication bypass in OpenClaw’s Feishu webhook mode due to missing encryptKey, but no patches, PoC, or active exploitation information are provided.

    0000037
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more