Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-41362

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Apr 28, 2026
Vendor unknown

Description

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitimate events on different accounts by matching event_name and message_id parameters.

References