CVE-2026-41371: OpenClaw < 2026.3.28 - Privilege Escalation via chat.send Reset Command
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.28
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41371?
CVE-2026-41371 is classified as a privilege escalation vulnerability.
How do I fix CVE-2026-41371?
To fix CVE-2026-41371, upgrade OpenClaw to version 2026.3.28 or later.
What are the implications of CVE-2026-41371?
The implications of CVE-2026-41371 include unauthorized users potentially gaining admin-level access and affecting session management.
Who is affected by CVE-2026-41371?
Users of OpenClaw versions prior to 2026.3.28 are affected by CVE-2026-41371.
How does CVE-2026-41371 exploit the system?
CVE-2026-41371 exploits the system by allowing write-scoped gateway callers to perform admin-only session reset operations.