Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35623

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 4.8
CVSS3: 6.5
EPSS Низкий

Описание

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to the webhook endpoint to compromise authentication and gain unauthorized access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Версия до 2026.3.25 (исключая)

EPSS

Процентиль: 29%
0.00361
Низкий

4.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 4.8
github
5 месяцев назад

OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

EPSS

Процентиль: 29%
0.00361
Низкий

4.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-307