PT-2026-34790 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-04-07
·
Updated
2026-04-25
·
CVE-2026-41359
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
Insufficient access controls allow authenticated operators with write permissions to perform privilege escalation. By utilizing the 'send' endpoint, attackers with
operator.write credentials can access administrative Telegram configuration and cron persistence settings, enabling the modification of persistence mechanisms.Recommendations
Update to version 2026.3.28 or later.
Restrict access to the 'send' endpoint for users with operator permissions until the update is applied.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw