CVE-2026-41349Patch(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-24); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-24: 3Mentions · 2026-04-25: 1Patch / Workaround · 2026-04-24: 3Technical Details · 2026-04-24: 3Technical Details · 2026-04-25: 104-2404-25
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-243
Patch3
2026-04-251
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 3 high severity #vulnerabilities in #OpenClaw. #CVE-2026-41352 #CVE-2026-41349 #CVE-2026-41353 CVSS: 8.8-8.1. A remote attacker with low privileges can exploit these vulnerabilities to execute code remotely #RCE. See https://ccb.belgium.be/advisories/warning-3-high-severity-vulnerabilities-openclaw-can-lead-rce-patch-immediately #Patch #Patch #Patch

    Post summary

    The post alerts users to three high‑severity vulnerabilities in OpenClaw, provides technical details and urges immediate patching.

    00010210
    7.2K followersView on X
  • Sattyam Jain@Sattyamjjain
    Patch

    Three books of primary sources on this week alone: 1. Anthropic postmortem: http://anthropic.com/engineering/april-23-postmortem 2. The Register wrap: http://theregister.com/2026/04/23/anthropic_says_it_has_fixed 3. CVE-2026-41349 (consent-bypass, Apr 23)

    Post summary

    The content summarizes Anthropic’s postmortem and The Register’s report that the consent‑bypass CVE-2026-41349 has been fixed.

    1000055
    66 followersView on X
  • Sattyam Jain@Sattyamjjain
    Patch

    This is why I shipped agent-airlock v0.5.3 last week with policy_presets: Each guard freezes the security policy at construction, takes a SHA-256 digest, and re-verifies before every tool call. CVE-2026-41349 (OpenClaw consent-bypass, Apr 23) is the exact class.

    Post summary

    The text announces the release of agent‑airlock v0.5.3 to mitigate the OpenClaw consent‑bypass CVE‑2026‑41349.

    1000057
    66 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41349 OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remo… https://www.cve.org/CVERecord?id=CVE-2026-41349

    Post summary

    CVE‑2026‑41349 is a newly disclosed agentic consent bypass in OpenClaw that allows LLM agents to disable execution approval via the config.patch parameter, with no evidence of exploitation or patches at this time.

    00000112
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more