Junglewise Threat Intelligence

CVE-2026-35646: OpenClaw Synology Chat rate limit bypass in webhook authentication

CVE-2026-35646 · Severity: medium · CVSS 4 · Published 2026-03-29

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a library used for Synology Chat integrations, contains a security flaw in how it handles webhook authentication. Because the system does not limit the number of failed login attempts, an attacker could repeatedly guess security tokens until they gain unauthorized access. This could allow an attacker to send unauthorized messages or intercept communications within the chat platform.

Technical details

A vulnerability exists in OpenClaw's Synology Chat webhook authentication mechanism due to improper restriction of excessive authentication attempts (CWE-307). The component rejected invalid tokens without implementing any throttling or rate-limiting on repeated guesses. A remote, unauthenticated attacker can exploit this by performing a brute-force attack against the webhook secret. If the secret is weak, the attacker can successfully guess the token to gain unauthorized access to the webhook functionality. The issue is addressed in version 2026.3.25 (and later 2026.3.28) by adding repeated-guess throttling before returning authentication failure responses.

Affected products

  • OpenClaw openclaw <= 2026.3.24

Timeline

  • 2026-03-26: disclosed: Initial disclosure and publication in openclaw repository
  • 2026-03-29: advisory: GitHub Advisory published
  • 2026-03-25: patched: First patched version 2026.3.25 released

References

Related threats