CVE-2026-41350: Openclaw
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to enforce configured tools.sessions.visibility restrictions for unsandboxed invocations. Attackers can invoke session_status without sandbox constraints to bypass session-policy controls and access restricted session information.
Affected products
- Openclaw Openclaw: before 2026.3.31 (fixed in 2026.3.31)
Published 2026-04-23. Last modified 2026-06-17.