CVE-2026-41394: Openclaw
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can access these routes without authentication to perform privileged runtime actions intended for authorized operators.
Affected products
- Openclaw Openclaw: before 2026.3.31 (fixed in 2026.3.31)
Published 2026-04-28. Last modified 2026-06-17.