Junglewise Threat Intelligence

CVE-2026-41362: OpenClaw improper cache isolation in Zalo webhook deduplication

CVE-2026-41362 · Severity: medium · CVSS 4.3 · Published 2026-04-28

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing webhooks, contains a flaw in how it handles Zalo messaging events across different accounts. In environments where multiple accounts are managed, an attacker who controls one account can intentionally block or suppress legitimate notifications and messages intended for other accounts. This results in a service disruption where important business events or customer communications may never be received by the intended recipient.

Technical details

An improper cache isolation vulnerability (CWE-668) exists in OpenClaw's Zalo webhook replay-dedupe mechanism. The deduplication cache was shared across authenticated webhook targets and keyed too broadly using only event_name and message_id. In multi-account deployments, an attacker who can send authenticated Zalo webhooks to their own path can pre-populate the shared cache with specific IDs. This causes the system to incorrectly identify legitimate incoming events for other accounts as duplicate 'replays,' leading to silent event suppression. The vulnerability was addressed in version 2026.3.31 by scoping the cache keys to specific paths and accounts.

Affected products

  • OpenClaw OpenClaw >= 2026.2.19, < 2026.3.31

Timeline

  • 2026-03-31: patched: Initial fix released in version 2026.3.31
  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-28: disclosed: NVD publication date

References

Related threats