CVE-2026-44116 | OpenClaw up to 2026.4.21 Zalo Bot API server-side request forgery (GHSA-2hh7-c75g-qj2r)
A vulnerability labeled as critical has been found in OpenClaw up to 2026.4.21. Impacted is an unknown function of the component Zalo Bot API. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-44116. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.