CVE-2026-41406: OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted Messages
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context messages to bypass sender allowlist restrictions and retrieve unauthorized content.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41406?
CVE-2026-41406 is categorized as a medium severity vulnerability due to the potential for unauthorized access to restricted messages.
How do I fix CVE-2026-41406?
To mitigate CVE-2026-41406, upgrade to OpenClaw version 2026.3.31 or later, which addresses the sender allowlist bypass issue.
What types of attacks are possible with CVE-2026-41406?
CVE-2026-41406 allows attackers to exploit thread history and quoted messages to gain unauthorized access to restricted content.
Which software versions are affected by CVE-2026-41406?
CVE-2026-41406 affects OpenClaw versions prior to 2026.3.31.
Is CVE-2026-41406 easily exploitable?
Yes, CVE-2026-41406 can be exploited by remote attackers with low complexity, making it a significant security concern.