Impact
An authorization bypass exists in OpenClaw webhook TaskFlow cancellation logic that allows an attacker with a valid webhook route secret to supply a child session key and cancel sessions outside the route’s intended scope. This flaw can lead to interruption of ongoing processes or denial of service to legitimate users.
Affected Systems
The vulnerability affects the OpenClaw product from the vendor OpenClaw in all releases prior to version 2026.8.1.
Risk and Exploitability
The CVSS base score is 2.3, indicating low severity. No EPSS information is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires possession of a webhook route secret, but the CVE description does not state how an attacker might acquire it; the likely ways (such as compromised credentials or insecure secret disclosure) are inferred but not explicitly documented in the official description, and then the attacker can trigger session cancellation via the exposed API.
OpenCVE Enrichment