PT-2026-29256 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-33576

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subsequently rejected.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33576

Affected Products

Openclaw