OpenClaw vulnerability

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heuristics to send unauthenticated webhook events to the BlueBubbles plugin.

Published 21 Mar 2026Updated 17 Sep 20264 sources
CVSS 6.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.