Junglewise Threat Intelligence

CVE-2026-45005: OpenClaw stale webhook route secret cache after rotation

CVE-2026-45005 · Severity: medium · CVSS 6 · Published 2026-05-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool for managing webhook task flows, contains a flaw where security credentials for webhooks remain valid even after they have been rotated by an administrator. This means an individual who previously had access could continue to trigger automated tasks and workflows despite attempts to revoke their access. The issue persists until the entire application or gateway is manually restarted.

Technical details

OpenClaw webhooks utilize a caching mechanism for route secrets backed by SecretRef values. When an operator rotates a secret and executes the 'openclaw secrets reload' command, the system fails to clear the previously resolved secret from the cache. Consequently, the stale credential remains authorized for webhook requests until the plugin or gateway process is restarted. This vulnerability is classified as Insufficient Session Expiration (CWE-613). An attacker with a previously valid secret can maintain access to invoke webhook task flows. The fix, introduced in version 2026.4.23, ensures that SecretRef-backed secrets are resolved on every request.

Affected products

  • OpenClaw openclaw < 2026.4.23

Timeline

  • 2026-04-24: disclosed: Initial disclosure by reporter
  • 2026-04-24: patched: Fix version 2026.4.23 released
  • 2026-05-05: advisory: GitHub Advisory published

References

Related threats