CVE-2026-41371Disclosure(openclaw / openclaw)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-28: 3Mentions · 2026-06-05: 1Technical Details · 2026-04-28: 2Technical Details · 2026-06-05: 104-2806-05
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure2General1
2026-06-051
Disclosure1
Full discourse4 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-41371: high severity (CVSS 8.5). OpenClaw has a remote code execution issue worth scoping now. The calm team is usually the team that practiced the boring parts.

    Post summary

    The text announces a new CVE (CVE-2026-41371) with a remote code execution flaw in OpenClaw, rating CVSS 8.5, but offers no PoC, exploit, or patch details.

    1000047
    311 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High Arbitrary File Write & Privilege Escalation in OpenClaw. #CVE-2026-41364 CVSS: 8.1 & #CVE-2026-41371 CVSS: 8.5. Symlink abuse in SSH sandbox tar upload may overwrite files, while auth callers can trigger admin-only session resets! #Patch #Patch #Patch

    Post summary

    The post alerts to two high‑severity CVEs in OpenClaw (arbitrary file write and privilege escalation) but gives no PoC, exploit code, evidence of active exploitation, or patch details.

    01000154
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41371 Privilege Escalation in OpenClaw Before 2026.3.28 Chat.Send Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41371

    Post summary

    The text announces a privilege‑escalation vulnerability in OpenClaw’s Chat.Send function affecting pre‑2026.3.28 versions, with no evidence of exploitation, patch, or PoC provided.

    0000047
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41371 📊 Severity: 8.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41371 #CVE-2026-41371 #CVE #High #CyberSecurity #InfoSec https://t.co/BD97KpAYKk

    Post summary

    The tweet announces CVE‑2026‑41371 with a high severity score, but provides no technical details, exploit information, or mitigation advice.

    0000039
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more