CVE-2026-29613
Last modified
CVE-2026-29613 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operates behind a reverse proxy, unauthenticated remote attackers can inject arbitrary BlueBubbles message and reaction events by reaching the proxy endpoint.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operates behind a reverse proxy, unauthenticated remote attackers can inject arbitrary BlueBubbles message and reaction events by reaching the proxy endpoint.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.2.12 |
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-xc7w-v5x6-cc87Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-29613?
How severe is CVE-2026-29613?
How do I fix CVE-2026-29613?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-29608OpenClaw 2026.3.1 contains an approval integrity vulnerabili…6.7
- CVE-2026-29609OpenClaw versions prior to 2026.2.14 contain a denial of ser…8.7
- CVE-2026-2961A vulnerability has been found in D-Link DWR-M960 1.01.07. T…8.8
- CVE-2026-29610OpenClaw versions prior to 2026.2.14 contain a command hijac…8.8
- CVE-2026-29611OpenClaw versions prior to 2026.2.14 contain a local file in…8.2
- CVE-2026-29612OpenClaw versions prior to 2026.2.14 decode base64-backed me…7.5
- CVE-2026-2962A vulnerability was found in D-Link DWR-M960 1.01.07. This v…8.8
- CVE-2026-29628A stack overflow in the experimental/tinyobj_loader_opt.h fi…6.2
- CVE-2026-2963A vulnerability was determined in Jinher OA C6 up to 2026021…6.3
- CVE-2026-2964A vulnerability was identified in higuma web-audio-recorder-…9.8
- CVE-2026-29642A local attacker who can execute privileged CSR operations (…7.8
- CVE-2026-29643XiangShan (Open-source high-performance RISC-V processor) co…7.1
Are you affected by CVE-2026-29613?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
