CVE-2026-32896 Details
Description
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heuristics to send unauthenticated webhook events to the BlueBubbles plugin.
A vulnerability exists in OpenClaw versions prior to 2026.2.21 within the BlueBubbles webhook handler. This vulnerability allows unauthenticated webhook events to be sent under certain reverse-proxy or local routing configurations. The issue arises from a passwordless fallback authentication path, which can be exploited by sending unauthenticated webhook events to the BlueBubbles plugin, bypassing the intended authentication requirements.
Users should upgrade to OpenClaw version 2026.2.21 or later, and ensure that the BlueBubbles webhook delivery includes a matching password. Instructions for updating can be found in the OpenClaw documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.2.21 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| Mar 23, 2026 | Initial Analysis | [email protected] |
| Mar 21, 2026 | New CVE Received | [email protected] |