CVE-2026-41910: OpenClaw < 2026.4.8 - Missing Owner-Only Enforcement in /allowlist Cross-Channel Writes
OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist modifications against different channels, violating the intended trust model.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41910?
CVE-2026-41910 has been classified as a high severity vulnerability due to the potential for unauthorized modification of the allowlist.
How do I fix CVE-2026-41910?
To fix CVE-2026-41910, upgrade OpenClaw to version 2026.4.8 or later, which implements the necessary owner-only access controls.
What is the impact of CVE-2026-41910?
The impact of CVE-2026-41910 allows unauthorized users to modify allowlist entries, potentially compromising system integrity.
Who is affected by CVE-2026-41910?
All users of OpenClaw versions prior to 2026.4.8 are affected by CVE-2026-41910 and should take immediate action.
Is there a workaround for CVE-2026-41910?
There is no official workaround; upgrading to the fixed version is necessary to mitigate CVE-2026-41910.