CVE-2026-41403

OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRemoteViewer is disabled, allowing unauthorized access. Attackers can bypass access controls by sending proxied requests that are incorrectly identified as local loopback traffic, circumventing intended remote viewer restrictions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

30 Apr 2026, 17:40

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/30a1690323088fd291abd11643a264a6828a002c - () https://github.com/openclaw/openclaw/commit/30a1690323088fd291abd11643a264a6828a002c - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-3xv9-89fm-7h4r - () https://github.com/openclaw/openclaw/security/advisories/GHSA-3xv9-89fm-7h4r - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-access-control-bypass-via-proxied-remote-request-misclassification - () https://www.vulncheck.com/advisories/openclaw-access-control-bypass-via-proxied-remote-request-misclassification - Third Party Advisory

28 Apr 2026, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 19:37

Updated : 2026-04-30 17:40


NVD link : CVE-2026-41403

Mitre link : CVE-2026-41403

CVE.ORG link : CVE-2026-41403


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-807

Reliance on Untrusted Inputs in a Security Decision