CVE-2026-41394: OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can access these routes without authentication to perform privileged runtime actions intended for authorized operators.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41394?
The severity of CVE-2026-41394 is classified as high, with a CVSS score of 8.8.
How do I fix CVE-2026-41394?
CVE-2026-41394 can be fixed by applying the available patch for OpenClaw version 2026.3.31 or later.
What kind of vulnerability is CVE-2026-41394?
CVE-2026-41394 is an authentication bypass vulnerability affecting unauthenticated plugin-auth routes in OpenClaw.
Which software is affected by CVE-2026-41394?
CVE-2026-41394 affects OpenClaw versions prior to 2026.3.31.
What actions can attackers perform due to CVE-2026-41394?
Due to CVE-2026-41394, attackers can perform privileged runtime actions intended for authorized operators without authentication.