Junglewise Threat Intelligence

OpenClaw BlueBubbles webhook authentication bypass

Severity: low · CVSS 3.1 · Published 2026-03-21

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a messaging platform with an optional BlueBubbles plugin that enables iMessage integration. The plugin's webhook handler contained a passwordless fallback authentication path that could allow attackers to send unauthenticated webhook events in certain reverse-proxy or local routing configurations, potentially enabling unauthorized message injection or other malicious actions without proper authentication.

Technical details

The vulnerability exists in the BlueBubbles webhook handler (extensions/bluebubbles component) which implemented multiple authentication branches including a passwordless fallback with loopback/proxy heuristics. An attacker can exploit this by sending unauthenticated webhook events to bypass authentication in deployments using the optional BlueBubbles plugin where webhook password authentication was not explicitly configured. The attack vector requires network access and is aided by reverse-proxy or local routing configurations. The fix consolidates authentication to a single required codepath: inbound webhook token/guid must match channels.bluebubbles.password, and BlueBubbles config validation now requires a password when serverUrl is set. Patches are available in version 2026.2.21 and later.

Affected products

  • OpenClaw openclaw <=2026.2.19-2

Timeline

  • 2026-02-21: disclosed
  • 2026-02-21: patched: Patched version 2026.2.21

References

Related threats