CVE-2026-41340

MEDIUM

OpenClaw < 2026.3.31 - Authentication Boundary Bypass via Telegram Legacy allowFrom Migration

Title source: cna

Description

OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named accounts. Attackers can exploit this trust propagation to bypass authentication controls and gain unauthorized access to named accounts.

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 18.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-372
Status published
Products (2)
OpenClaw/OpenClaw < 2026.3.31
OpenClaw/OpenClaw 2026.3.31
Published Apr 23, 2026
Tracked Since Apr 24, 2026