
CVE-2026-33580 OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared… https://www.cve.org/CVERecord?id=CVE-2026-33580
Post summary
The text reports a missing rate‑limiting flaw in OpenClaw’s Nextcloud Talk webhook authentication that permits brute‑force attempts, but provides no PoC, exploit, patch, or evidence of active exploitation.


