PT-2026-35559 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-04-27
·
Updated
2026-06-05
·
CVE-2026-41371
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
Improper authorization checks in the 'chat.send' path allow write-scoped gateway callers to perform admin-only session reset operations. This enables attackers to rotate target sessions, archive previous transcript states, and force the generation of new session IDs without possessing the required admin scope.
Recommendations
Update to version 2026.3.28 or later.
As a temporary workaround, restrict access to the 'chat.send' function to minimize the risk of unauthorized session resets.
Fix
LPE
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw