CVE-2026-41344

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026

Description

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist admin-only verboseLevel session overrides. Attackers can exploit the /verbose parameter to bypass access controls and expose sensitive reasoning or tool output intended to be restricted to administrators.