PT-2026-35777 · Openclaw · Openclaw

Keensecuritylab

+2

·

Published

2026-04-03

·

Updated

2026-04-30

·

CVE-2026-41393

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A wide-area discovery issue allows arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet position and CA-trusted endpoint access can exfiltrate operator credentials by manipulating DNS steering.
Recommendations Update to version 2026.3.31.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41393
GHSA-Q9W8-CF67-R238

Affected Products

Openclaw