Junglewise Threat Intelligence

CVE-2026-41406: OpenClaw sender allowlist bypass via thread history and quoted messages

CVE-2026-41406 · Severity: low · CVSS 3.1 · Published 2026-04-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Feishu (a business messaging platform) integration library used to manage message workflows and access controls. When processing thread histories and quoted messages, the library fails to enforce sender allowlists, allowing unauthorized users to view or interact with restricted content. This bypass undermines message security policies that organizations rely on to protect sensitive communications.

Technical details

The vulnerability is an authorization bypass (CWE-639, CWE-863) in OpenClaw's Feishu message handling. When the library fetches quoted messages, root messages, or thread context data, it does not enforce the configured sender allowlist on these fetched messages, allowing messages from non-allowlisted senders to be accessed or displayed. The attack requires user interaction (clicking a link or viewing a thread with quoted context) over the network. An attacker can craft a message containing quotes or threads that reference restricted content, bypassing the allowlist controls. The fix is available in version 2026.3.31 and later.

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-04-02: disclosed: Advisory published
  • 2026-03-31: patched: Fix committed and released in v2026.3.31

References

Related threats