PT-2026-34709 · Openclaw · Openclaw

Zou Dikai

·

Published

2026-04-23

·

Updated

2026-04-28

·

CVE-2026-41908

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.20
Description A scope enforcement bypass exists in the 'assistant-media' route. This allows trusted-proxy callers who lack the operator.read scope to bypass identity-bearing HTTP auth path scope validation. Consequently, unauthorized users can access protected assistant-media files and metadata, enabling the retrieval of sensitive media content within allowed media roots.
Recommendations Update to version 2026.4.20.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-41908
GHSA-QGX9-6PX9-7P75
GHSA-V8QF-FR4G-28P2

Affected Products

Openclaw