Improper access control in OpenClaw - CVE-2026-41346
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in pending pairing-request cap enforcement when handling pairing requests in multi-account channel setups. A remote user can submit pairing requests from another account to cause a denial of service.
The issue is limited to availability and does not allow cross-account approval, data access, or authorization bypass.