CVE-2026-41405CWE-408

OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing

High · published April 28, 2026

CVSS v4.0
8.7
EPSS
0%
Percentile
39.8
In the wild
Unconfirmed
What it is

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing authentication checks.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00481 · 39.8th percentile
Weakness
CWE-408 · Incorrect Behavior Order: Early Amplification
Published
2026-04-28T18:10Z
EPSS history
Timeline
  • 28 APR 18:10Z
    OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
    cvelistv5