← Zurück zur CVE-Suche

CVE-2026-41359

OpenClaw

Beschreibung

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Telegram configuration and cron persistence settings via the send endpoint. Attackers with operator.write credentials can exploit insufficient access controls to reach sensitive administrative functionality and modify persistence mechanisms.

CVSS 7.1EPSS 0.232%Risiko 0.72
Quelle öffnen
Veröffentlicht
2026-04-23 22:16:43
Betroffene Versionen
<2026.3.28
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N