CVE-2026-41381: OpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist
OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level member access allowlist restrictions. Attackers can send Discord voice ingress requests before channel allowlist authorization is performed, gaining unauthorized access to restricted voice channels.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41381?
CVE-2026-41381 is classified as a medium severity access control bypass vulnerability.
How do I fix CVE-2026-41381?
To fix CVE-2026-41381, upgrade OpenClaw to version 2026.3.31 or later.
What are the possible impacts of CVE-2026-41381?
The impact of CVE-2026-41381 includes unauthorized access to Discord voice channels, allowing attackers to bypass member access restrictions.
Which versions of OpenClaw are affected by CVE-2026-41381?
OpenClaw versions prior to 2026.3.31 are affected by CVE-2026-41381.
Can CVE-2026-41381 be exploited remotely?
Yes, CVE-2026-41381 can be exploited remotely by attackers who target the Discord voice manager.