CVE-2026-41910
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
28/04/2026
Last modified:
28/04/2026
Description
OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist modifications against different channels, violating the intended trust model.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
4.30
Severity 3.x
MEDIUM



