CVE-2026-44109 Details
Description
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands.
An authentication bypass vulnerability has been identified in OpenClaw versions prior to 2026.4.15. This vulnerability exists in the Feishu webhook and card-action validation processes, allowing unauthenticated requests to bypass signature verification and replay protection, ultimately reaching the command dispatch system. The issue arises because the Feishu integration can accept requests without a proper 'encryptKey' and allows blank callback tokens to be used, creating a fail-open scenario. As a result, attackers can exploit this vulnerability to execute arbitrary commands on the affected system.
Users can upgrade to OpenClaw version 2026.4.15 or later, which addresses this vulnerability by ensuring that the Feishu webhook requires a valid 'encryptKey' and rejects blank callback tokens before processing card-action events.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.4.15 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | [email protected] |