Loading market data...
← Back to CVE feed

CVE-2026-41406

MEDIUM CVSS 5.4 View on NVD ↗

Description

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context messages to bypass sender allowlist restrictions and retrieve unauthorized content.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Published: Apr 28, 2026 19:37 UTC Modified: Apr 28, 2026 20:10 UTC