Loading market data...
← Back to CVE feed

CVE-2026-41353

HIGH CVSS 8.1 View on NVD ↗

Description

OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Published: Apr 23, 2026 22:16 UTC Modified: Apr 24, 2026 14:40 UTC