Loading market data...
← Back to CVE feed

CVE-2026-41371

HIGH CVSS 8.5 View on NVD ↗

Description

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Affected Products

openclaw/openclaw
Published: Apr 28, 2026 00:16 UTC Modified: Apr 28, 2026 18:44 UTC