CVE-2026-41398: OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge
OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. Attackers can inject unauthorized agent.request runs by loading attacker-controlled pages from local-network or tailnet hosts, polluting session state and consuming budget.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41398?
CVE-2026-41398 has been classified with a high severity due to its potential for unauthorized access and exploitation in local networks.
How do I fix CVE-2026-41398?
To fix CVE-2026-41398, update OpenClaw to version 2026.4.2 or later, which addresses the improper access control vulnerability.
What types of devices are affected by CVE-2026-41398?
CVE-2026-41398 affects devices running the OpenClaw software, particularly those using the iOS A2UI bridge prior to version 2026.4.2.
Can CVE-2026-41398 be exploited remotely?
No, CVE-2026-41398 requires local network access to exploit the vulnerability, allowing attackers to inject unauthorized requests.
Who is responsible for the vulnerability tracking of CVE-2026-41398?
The vulnerability tracking for CVE-2026-41398 is managed by the NVD and OpenClaw's development team.