Junglewise Threat Intelligence

CVE-2026-41378: OpenClaw privilege escalation via unrestricted node.event dispatch

CVE-2026-41378 · Severity: low · CVSS 3.1 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a distributed node-based application framework. A paired node (an authenticated internal node) can escalate privileges by manipulating node.event agent requests to gain broader gateway-side tool access than normally permitted. The vulnerability requires an attacker to already have authenticated node access, so the practical impact is limited to scenarios where a node has been compromised—in such cases, the attacker can move laterally to gain full remote code execution on the gateway.

Technical details

The vulnerability is a missing authorization check (CWE-862, CWE-863) in OpenClaw's node.event agent dispatch mechanism. A paired node with role=node can craft agent.request messages that bypass intended RPC restrictions and access broader gateway-side tools, leading to remote code execution on the gateway. The attack requires network access to the OpenClaw cluster and prior compromise of a paired node; it does not require user interaction. Exploitation allows an attacker with node-level access to escalate to full gateway code execution. The vulnerability affects OpenClaw versions up to 2026.3.28 and is fixed in version 2026.3.31 (commit a77928b1087e90f2a8903f8e5aca6dec9237ac62).

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-04-03: disclosed: Advisory published on GitHub and OSV
  • 2026-03-31: patched: Fix released in version 2026.3.31

References

Related threats