PT-2026-38238 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-04-17

·

Updated

2026-05-07

·

CVE-2026-43583

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.10 through 2026.4.13
Description An issue exists where session context is not persisted during delivery queue recovery for media replay. This allows attackers to exploit recovered queued outbound media to bypass group tool policy enforcement and weaken channel media restrictions following a service restart or recovery.
Recommendations Update to version 2026.4.14.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-43583
GHSA-82RM-QCFX-2V78
GHSA-R77C-2CMR-7P47

Affected Products

Openclaw