Junglewise Threat Intelligence

CVE-2026-41910: OpenClaw authorization bypass in cross-channel allowlist writes

CVE-2026-41910 · Severity: low · CVSS 3.1 · Published 2026-04-09

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a local AI assistant that manages user permissions through an allowlist mechanism to control which senders can perform actions on different channels. A flaw in this permission system allows an authorized non-owner user to write to the allowlist of a channel they do not own, potentially granting themselves unauthorized access to manage permissions on channels belonging to other users.

Technical details

The vulnerability is a missing authorization check (CWE-863) in the /allowlist endpoint that fails to properly enforce owner-only permissions for cross-channel writes. An authenticated non-owner user can craft requests to modify the allowlist of a different channel, bypassing ownership validation. The attack requires prior authorization in the system but no additional user interaction. An attacker can manipulate allowlists to modify channel access controls, though the vulnerability is scoped to the single-user trust model of OpenClaw rather than multi-tenant deployments. The issue has been fixed in version 2026.4.8 (commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5).

Affected products

  • OpenClaw openclaw <=2026.4.1

Timeline

  • 2026-04-09: disclosed
  • 2026-04-08: patched: Fixed in version 2026.4.8

References

Related threats