Junglewise Threat Intelligence

CVE-2026-41340: OpenClaw auth boundary bypass in Telegram legacy allowFrom migration

CVE-2026-41340 · Severity: medium · CVSS 4 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library that manages account authentication and Telegram bot integration. A legacy migration flaw inadvertently grants Telegram's default account credentials to all other named accounts, allowing unauthorized access and potential account takeover. The vulnerability affects versions up to 2026.3.28 and is patched in 2026.3.31.

Technical details

The vulnerability is an authentication boundary bypass (CWE-732) introduced during legacy allowFrom migration for Telegram account pairing. The flaw causes the default account's trust credentials to be incorrectly propagated to all named accounts during account resolution. Attack preconditions are minimal: any system using the vulnerable OpenClaw versions with Telegram integration is affected. An attacker with knowledge of the default account's allowFrom rules can impersonate that account through any named account, achieving privilege escalation and unauthorized Telegram bot access. The fix (commit d8c68c8d) properly restricts allowFrom migration to the default account only and is available in version 2026.3.31 and later.

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-04-03: disclosed
  • 2026-03-31: patched: Fix commit d8c68c8d; patched version 2026.3.31 released

References

Related threats