PT-2026-34790 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-04-07

·

Updated

2026-04-25

·

CVE-2026-41359

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description Insufficient access controls allow authenticated operators with write permissions to perform privilege escalation. By utilizing the 'send' endpoint, attackers with operator.write credentials can access administrative Telegram configuration and cron persistence settings, enabling the modification of persistence mechanisms.
Recommendations Update to version 2026.3.28 or later. Restrict access to the 'send' endpoint for users with operator permissions until the update is applied.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41359
GHSA-394X-274P-MQC6
GHSA-767M-XRHC-FXM7

Affected Products

Openclaw