Junglewise Threat Intelligence

CVE-2026-41908: OpenClaw assistant media route scope enforcement bypass

CVE-2026-41908 · Severity: low · CVSS 3.1 · Published 2026-04-25

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library providing UI components and API integration for enterprise assistants. The Control UI assistant-media route failed to enforce operator-level access controls for certain callers, allowing users without proper read permissions to access assistant media files and metadata that should have been restricted. While the vulnerability requires successful gateway authentication and valid media-root configuration, it bypasses intended authorization checks.

Technical details

The vulnerability is an authorization bypass (CWE-863) in the assistant-media HTTP route handler. The affected component authenticated trusted-proxy callers using gateway authentication but did not validate that callers possessed the required operator.read scope before granting access to identity-bearing HTTP auth paths. A trusted-proxy caller lacking operator.read scope could read assistant-media files and metadata within allowed media roots. The attack is network-accessible and requires only authentication as a low-privileged trusted-proxy account; no additional user interaction is needed. The fix (commit 99ef3a63c58440d53f8e45ad861b846032fcb036) enforces operator.read scope validation for all assistant-media file and metadata requests on identity-bearing auth paths. OpenClaw 2026.4.20 and later are patched.

Affected products

  • OpenClaw OpenClaw < 2026.4.20

Timeline

  • 2026-04-25: disclosed
  • 2026-04-25: patched: OpenClaw 2026.4.20 released

References

Related threats