CVE-2026-42433Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate persistent profile configuration through non-owner message-tool runs.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-05: 2Technical Details · 2026-05-05: 205-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42433 OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring adm… https://www.cve.org/CVERecord?id=CVE-2026-42433

    Post summary

    CVE‑2026‑42433 identifies an authorization bypass in OpenClaw before 2026.4.10, enabling unauthorized access to Matrix profile persistence, but no PoC, exploit, or patch details are provided.

    00010191
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42433 OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring adm… https://www.cve.org/CVERecord?id=CVE-2026-42433 ----- Traducción: CVE-2026-42433 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces the disclosure of CVE‑2026‑42433 for OpenClaw, describing an authorization bypass that could allow unauthorized access via certain message‑tool paths to Matrix profile persistence.

    0000044
    75 followersView on X

Explore more