Medium severity6.5NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-53830
CVE-2026-53830
Description
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-275c-xpvc-jgfwnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-webhook-secret-revocation-bypass-via-secrets-reloadnvdThird Party Advisory
News mentions
1- OpenClaw: 25 CVEs Disclosed in Largest Security Batch, Including Code Execution and Critical Auth BypassVypr Intelligence · Jun 12, 2026