
CVE-2026-35623 OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without… https://www.cve.org/CVERecord?id=CVE-2026-35623
Post summary
The post announces a missing rate‑limiting flaw in OpenClaw's webhook authentication that permits brute‑forcing of weak passwords, with no PoC, tool, or patch mentioned.
