PT-2026-34775 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-03-31
·
Updated
2026-04-25
·
CVE-2026-41344
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
A privilege escalation issue exists in the "chat.send" endpoint. Write-scoped gateway callers can persist admin-only
verboseLevel session overrides by exploiting the /verbose parameter. This allows attackers to bypass access controls and expose sensitive reasoning or tool output that should be restricted to administrators.Recommendations
Update to version 2026.3.28 or later.
As a temporary workaround, restrict access to the
/verbose parameter in the "chat.send" endpoint.Fix
LPE
Improper Access Control
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw