📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 26m Global general Technology / Consumer Protection MEDIUM 37m Global vulnerability Information Technology and Security CRITICAL 45m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 26m Global general Technology / Consumer Protection MEDIUM 37m Global vulnerability Information Technology and Security CRITICAL 45m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 26m Global general Technology / Consumer Protection MEDIUM 37m Global vulnerability Information Technology and Security CRITICAL 45m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2026-45005

Medium
CWE-672 — Weakness Type
Published: May 11, 2026  ·  Modified: May 14, 2026  ·  Source: NVD
CVSS v3
6.0
🔗 NVD Official
📄 Description (English)

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.

🤖 AI Executive Summary

OpenClaw before version 2026.4.23 contains a credential caching vulnerability (CWE-672) where webhook route secrets remain valid after rotation due to improper cache invalidation. Attackers with previously compromised webhook secrets can continue authenticating and invoking webhook tasks until system restart. While no public exploit exists, the vulnerability poses a moderate risk to organizations using OpenClaw for webhook orchestration, particularly those with frequent secret rotation policies.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 11:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using OpenClaw for API integration and webhook orchestration face moderate risk, particularly in: (1) Banking sector (SAMA-regulated) — if OpenClaw manages payment webhook flows or transaction notifications; (2) Government agencies (NCA oversight) — if used for inter-agency API communication; (3) Telecom operators (STC, Mobily) — if managing customer notification webhooks; (4) E-commerce platforms — if processing order and payment webhooks. The vulnerability's impact is amplified in environments with strict secret rotation policies but delayed system restart cycles, allowing extended unauthorized access windows.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications E-commerce and Retail Healthcare Energy and Utilities
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Audit all webhook route secrets in OpenClaw instances and rotate them immediately
2. Review webhook invocation logs for the past 90 days to identify suspicious activity
3. Implement network-level monitoring for webhook endpoint access patterns
4. Disable unused webhook routes and SecretRef configurations

Patching Guidance:
1. Upgrade OpenClaw to version 2026.4.23 or later when available
2. Until patch is available, implement compensating controls:
- Schedule weekly OpenClaw gateway and plugin restarts to flush credential cache
- Implement API gateway rate limiting on webhook endpoints
- Enable detailed audit logging for all webhook authentications

Detection Rules:
1. Monitor for webhook requests using credentials older than last rotation timestamp
2. Alert on webhook invocations from unexpected source IPs
3. Track failed webhook authentications followed by successful ones with same credential
4. Monitor OpenClaw logs for cache-related errors or warnings
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع أسرار مسار webhook في مثيلات OpenClaw وتدويرها فوراً
2. مراجعة سجلات استدعاء webhook لآخر 90 يوماً لتحديد النشاط المريب
3. تنفيذ المراقبة على مستوى الشبكة لأنماط الوصول إلى نقاط نهاية webhook
4. تعطيل مسارات webhook غير المستخدمة وتكوينات SecretRef

إرشادات التصحيح:
1. ترقية OpenClaw إلى الإصدار 2026.4.23 أو أحدث عند توفره
2. حتى توفر التصحيح، تنفيذ عناصر تحكم تعويضية:
- جدولة إعادة تشغيل بوابة OpenClaw والمكونات الإضافية أسبوعياً لمسح ذاكرة التخزين المؤقت
- تنفيذ تحديد معدل بوابة API على نقاط نهاية webhook
- تفعيل تسجيل التدقيق التفصيلي لجميع عمليات مصادقة webhook

قواعد الكشف:
1. مراقبة طلبات webhook باستخدام بيانات اعتماد أقدم من آخر طابع زمني للتدوير
2. تنبيه استدعاءات webhook من عناوين IP غير متوقعة
3. تتبع عمليات مصادقة webhook الفاشلة متبوعة بعمليات ناجحة بنفس بيانات الاعتماد
4. مراقبة سجلات OpenClaw للأخطاء أو التحذيرات المتعلقة بالذاكرة المؤقتة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 — Policies and procedures for access control ECC 2024 A.5.2.1 — User registration and access rights management ECC 2024 A.5.2.2 — Privileged access rights management ECC 2024 A.8.2.1 — User access provisioning and de-provisioning ECC 2024 A.8.3.1 — Management of privileged access rights
🔵 SAMA CSF
SAMA CSF ID.AM-2 — Software, hardware, and firmware inventory SAMA CSF PR.AC-1 — Access control policy and procedures SAMA CSF PR.AC-2 — Physical and logical access controls SAMA CSF DE.CM-1 — Detection and analysis of unauthorized access
🟡 ISO 27001:2022
ISO 27001:2022 A.5.2 — Position of information security ISO 27001:2022 A.8.2 — Information security onboarding ISO 27001:2022 A.8.3 — Access management ISO 27001:2022 A.9.2 — User access provisioning ISO 27001:2022 A.9.4 — Access rights review
🟣 PCI DSS v4.0.1
PCI DSS 2.1 — Inventory of network resources PCI DSS 3.2 — Cryptographic key management PCI DSS 7.1 — Limit access to system components PCI DSS 8.2 — User identification and authentication
📦 Affected Products / CPE 1 entries
openclaw:openclaw
📊 CVSS Score
6.0
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredH — High
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityH — High
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.0
CWECWE-672
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-05-11
Source Feed nvd
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-672
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.