
CVE-2026-41298 OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HTTP modes. Read-scoped callers can termina… https://www.cve.org/CVERecord?id=CVE-2026-41298
Post summary
The tweet announces a new OpenClaw vulnerability (CVE‑2026‑41298) that allows read‑scoped callers to terminate sessions due to missing scope enforcement. No PoC, patch, or exploitation evidence is provided.

