
CVE-2026-41394 OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attacke… https://www.cve.org/CVERecord?id=CVE-2026-41394
Post summary
The entry announces CVE‑2026‑41394, outlining that OpenClaw before version 2026.3.31 has an authentication bypass flaw allowing unauthenticated users to acquire operator write scopes, without mentioning PoC, exploit, or patch details.
