CVE-2026-33580Disclosure(openclaw / openclaw)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Disclousure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-31: 3Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 303-31
Signal classification2 categories
Disclosure
266.7%
Disclousure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33580 OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared… https://www.cve.org/CVERecord?id=CVE-2026-33580

    Post summary

    The text reports a missing rate‑limiting flaw in OpenClaw’s Nextcloud Talk webhook authentication that permits brute‑force attempts, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000089
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclousure

    [CVE-2026-33580: CRITICAL] Urgent: OpenClaw's Nextcloud Talk webhook authentication vulnerability discovered! Attackers can brute-force weak shared secrets to forge inbound webhook events. Update before 2026...#cve,CVE-2026-33580,#cybersecurity https://cvefind.com/CVE-2026-33580

    Post summary

    The tweet announces a critical authentication vulnerability in OpenClaw's Nextcloud Talk webhook that enables brute‑force forging of events, urging users to update before 2026.

    0000038
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33580 - Critical OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers w... https://www.thehackerwire.com/vulnerability/CVE-2026-33580/ https://t.co/JOLFMhk92j

    Post summary

    The tweet announces a critical CVE‑2026‑33580 vulnerability in OpenClaw before 2026.3.28 that lacks rate limiting and permits brute‑forcing weak shared secrets in Nextcloud Talk webhook authentication.

    0000038
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more