
CVE-2026-41356 OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials can maintain una… https://www.cve.org/CVERecord?id=CVE-2026-41356
Post summary
The tweet announces CVE‑2026‑41356, noting that OpenClaw’s token rotation does not terminate WebSocket sessions, allowing attackers with prior credentials to keep sessions alive, but provides no PoC, exploit, patch, or active exploitation details.
