CVE-2026-29606 | OpenClaw up to 2026.2.13 Publicly Reachable Webhook Endpoint missing authentication (GHSA-c37p-4qqg-3p76)
A vulnerability identified as critical has been detected in OpenClaw up to 2026.2.13. Affected by this vulnerability is an unknown functionality of the component Publicly Reachable Webhook Endpoint. This manipulation causes missing authentication.
This vulnerability appears as CVE-2026-29606. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.