CVE-2026-41362: Openclaw
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitimate events on different accounts by matching event_name and message_id parameters.
Affected products
- Openclaw Openclaw: from 2026.2.19, before 2026.3.31 (fixed in 2026.3.31)
Published 2026-04-28. Last modified 2026-07-24.