CVE 8.8 HIGH

OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes_CVE-2026-41394

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Description

OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can access these routes without authentication to perform privileged runtime actions intended for authorized operators.

AI Analysis

Authentication bypass vulnerability in unauthenticated plugin-auth HTTP routes

Basic Information

ID CVE-2026-41394
Source VulnCheck
Published Apr 28, 2026 at 18:09

Affected Product

Vendor OpenClaw
Product OpenClaw
Affected Versions OpenClaw OpenClaw 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor OpenClaw
Product OpenClaw
Version < 2026.3.31

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.