PT-2026-35764 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-04-07

·

Updated

2026-05-01

·

CVE-2026-41379

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description Authenticated operators with write permissions can escalate privileges to access admin-class Talk Voice configuration persistence. This is possible by exploiting the 'chat.send' endpoint to reach and modify sensitive voice configuration settings intended exclusively for administrators.
Recommendations Update to version 2026.3.28 or later. Restrict access to the 'chat.send' endpoint for users with operator.write privileges to minimize the risk of exploitation.

Fix

LPE

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-41379
GHSA-3Q42-XMXV-9VFR

Affected Products

Openclaw