5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Description
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.
Basic Information
ID
CVE-2026-41367
Source
VulnCheck
Published
Apr 27, 2026 at 23:24
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Version
2026.2.14
Affected Versions
OpenClaw OpenClaw 2026.2.14