{"id":"CVE-2026-33580","title":"OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets","summary":"OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-307"],"vendor":"openclaw","product":"openclaw","affected":["openclaw < 2026.3.28"],"patched":["openclaw 2026.3.28"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33580","references":[{"url":"https://github.com/openclaw/openclaw/commit/e403decb6e20091b5402780a7ccd2085f98aa3cd","label":"disclosure@vulncheck.com"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-9528-x887-j2fp","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-brute-force-attack-via-missing-rate-limiting-on-webhook-shared-secret-authentication","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00365,"epssPercentile":0.3033,"ingestedAt":"2026-07-24T21:39:13.193Z","slug":"CVE-2026-33580","body":"## Overview\n\nOpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.\n\n## Affected\n\n- `openclaw < 2026.3.28`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openclaw 2026.3.28`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}