CVE-2026-44109General(openclaw / openclaw)

LOWCVSS 9.2 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • General: 3 classified signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-07); latest day: 3
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-05-06: 1Mentions · 2026-05-07: 3Mentions · 2026-05-12: 1Mentions · 2026-05-14: 3Patch / Workaround · 2026-05-07: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 3Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 205-0605-0705-1205-14
Signal classification3 categories
General
337.5%
Disclosure
337.5%
Patch
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-061
General1
2026-05-073
Disclosure1Patch2
2026-05-121
Disclosure1
2026-05-143
Disclosure1General2
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-44109 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows…

    Post summary

    An advisory for a critical authentication bypass in OpenClaw’s Feishu webhook and card-action validation, providing vulnerability details but no PoC, exploit code, or mention of active exploitation or patches.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.8 CRITICAL · CVE-2026-44109 · 9.8 → 2026.4.15 CVE: CVE-2026-44109 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists CVE‑2026‑44109 with a CVSS score of 9.8 and the 'Critical' severity classification, but does not mention PoCs, exploit code, active exploitation, or any patch or mitigation details.

    1000033
    210 followersView on X
  • Lili@Lili_Ai_49
    Disclosure

    OpenClaw has a CVSS 9.8 auth bypass (CVE-2026-44109) and sandbox escape CVEs from early 2026. Most operators have zero runtime visibility. CISA issued a formal advisory on April 20, 2026. Damage assessment is still ongoing.

    Post summary

    A high‑severity auth bypass vulnerability (CVE-2026-44109) in OpenClaw was disclosed, accompanied by a CISA advisory, but no PoC, exploit, or patch details were provided.

    10000403
    402 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-44109 — CVSS 9.8/10 ██████████ OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/pLvFxFtc2y

    Post summary

    New critical authentication bypass vulnerability (CVE-2026-44109) in OpenClaw’s Feishu webhook with a patch now available.

    1000084
    28 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-44109-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided content consists merely of a URL with related hashtags, containing no explicit indicators of PoC, exploitation, or mitigation details.

    0000022
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44109 OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach c… https://www.cve.org/CVERecord?id=CVE-2026-44109

    Post summary

    A new authentication‑bypass vulnerability (CVE‑2026‑44109) in OpenClaw’s Feishu webhook and card‑action validation allows unauthenticated requests; no PoC, exploit, or patch details are provided.

    0000074
    57.4K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    Patch Priority: Gotenberg metadata handling flaw with likely internet exposure (CVSS 9.6-10.0) Affected: Gotenberg; Vvveb; OpenClaw Internet-facing exposure and authentication bypasses drive today's critical CVEs across containerized and web-app stacks. CVE-2026-40281 (CVSS 10.0) Gotenberg before 8.30.2 (8.30.1 and earlier) contains a metadata handling flaw in which unsanitized metadata values can trigger ExifTool injection, enabling renaming or moving PDFs to arbitrary paths within the container. https://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318 CVE-2026-44109 (CVSS 9.8) OpenClaw before 2026.4.15 has an authentication bypass in Feishu webhook and card-action validation, enabling unauthenticated requests to reach command dispatch and potentially bypass signature verification and replay protections. https://github.com/openclaw/openclaw/commit/c8003f1b33ed2924be5f62131bd28742c5a41aae CVE-2026-43575 (CVSS 9.8) OpenClaw before 2026.4.10 contains an authentication bypass in the sandbox noVNC helper route that exposes interactive browser session credentials. https://github.com/openclaw/openclaw/commit/19a2e9ddb5a8a494abcba812bb11f51075026a27 CVE-2026-41930 (CVSS 9.8) Vvveb before 1.0.8.2 ships with hard-coded credentials in docker-compose-apache.yaml, allowing unauthenticated access to the bundled phpMyAdmin container and its database credentials. https://github.com/givanz/Vvveb/commit/f85ca7c2bc389bda3cc2eca87b2514581a628c32 CVE-2026-43581 (CVSS 9.6) OpenClaw before 2026.4.10 has an improper network binding that exposes Chrome DevTools Protocol on 0.0.0.0, enabling access from outside the intended local sandbox. https://github.com/openclaw/openclaw/commit/fbf11ebdb7110632f93926d0ac7b48f04cb44d77 🛠️ Action • Patch/upgrade affected components to fixed versions or the latest vendor advisories. • Prioritize internet-facing instances and edge appliances first. • If no fix yet, apply mitigations such as restricting access or disabling vulnerable features. • Add detections for exploitation patterns: metadata injection attempts, auth bypass, and unauthorized DevTools access. • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF). • Validate remediation (version checks, config verification) and monitor for reversion.

    Post summary

    The post announces critical CVEs in Gotenberg, OpenClaw, and Vvveb, provides technical details and CVSS scores, and focuses on patching, mitigation, and monitoring measures.

    0000063
    103 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44109 Authentication Bypass in OpenClaw Before 2026.4.15 Feishu Webhook Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44109

    Post summary

    The snippet identifies CVE-2026-44109 as an authentication bypass in OpenClaw before version 2026.4.15 related to Feishu webhook validation, without providing further technical or actionable details.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more