CVE-2026-41344
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026
Description
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist admin-only verboseLevel session overrides. Attackers can exploit the /verbose parameter to bypass access controls and expose sensitive reasoning or tool output intended to be restricted to administrators.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
5.40
Severity 3.x
MEDIUM



