CVE-2026-42433: OpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message Tools
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate persistent profile configuration through non-owner message-tool runs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42433?
CVE-2026-42433 is considered a critical severity vulnerability due to unauthorized access to sensitive configurations.
How do I fix CVE-2026-42433?
To fix CVE-2026-42433, update OpenClaw to version 2026.4.10 or later, which includes the necessary security patches.
What does CVE-2026-42433 affect?
CVE-2026-42433 affects OpenClaw versions prior to 2026.4.10 by allowing unauthorized access to Matrix profile configurations.
Who is affected by CVE-2026-42433?
Organizations using OpenClaw versions before 2026.4.10 are at risk of exploitation from CVE-2026-42433.
What kind of attack can exploit CVE-2026-42433?
CVE-2026-42433 can be exploited by attackers to perform unauthorized actions requiring admin-level authority via operator.write message tools.