OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | 0 |
Updated description with new technical details, changed severity to HIGH, and marked as actively exploited.
Initial creation