CVE-2026-41349

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

29 Apr 2026, 14:40

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/76411b2afc4ae721e36c12e0ea24fd23e2fed61e - () https://github.com/openclaw/openclaw/commit/76411b2afc4ae721e36c12e0ea24fd23e2fed61e - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-v3qc-wrwx-j3pw - () https://github.com/openclaw/openclaw/security/advisories/GHSA-v3qc-wrwx-j3pw - Vendor Advisory, Patch
References () https://www.vulncheck.com/advisories/openclaw-agentic-consent-bypass-via-config-patch - () https://www.vulncheck.com/advisories/openclaw-agentic-consent-bypass-via-config-patch - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

23 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 22:16

Updated : 2026-04-29 14:40


NVD link : CVE-2026-41349

Mitre link : CVE-2026-41349

CVE.ORG link : CVE-2026-41349


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-862

Missing Authorization