CVE 8.7 HIGH

OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch_CVE-2026-41349

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent.

AI Analysis

Agentic consent bypass vulnerability via config.patch parameter

Basic Information

ID CVE-2026-41349
Source VulnCheck
Published Apr 23, 2026 at 21:58

Affected Product

Vendor OpenClaw
Product OpenClaw
Affected Versions OpenClaw OpenClaw 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor OpenClaw
Product OpenClaw
Version < 2026.3.28

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.