PT-2026-35789 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-41406

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context messages to bypass sender allowlist restrictions and retrieve unauthorized content.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-41406

Affected Products

Openclaw