CVE 5.3 MEDIUM

OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions_CVE-2026-41367

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Description

OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.

Basic Information

ID CVE-2026-41367
Source VulnCheck
Published Apr 27, 2026 at 23:24

Affected Product

Vendor OpenClaw
Product OpenClaw
Version 2026.2.14
Affected Versions OpenClaw OpenClaw 2026.2.14

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.