Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 15 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials. | |
| Title | OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-15T17:23:20.297Z
Reserved: 2026-06-10T21:16:58.211Z
Link: CVE-2026-53830
Updated: 2026-06-15T17:23:16.250Z
Status : Analyzed
Published: 2026-06-12T22:16:54.490
Modified: 2026-06-16T02:55:05.433
Link: CVE-2026-53830
No data.
OpenCVE Enrichment
Updated: 2026-06-13T00:45:06Z