Improper access control in OpenClaw - CVE-2026-41340
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass account trust boundaries.
The vulnerability exists due to improper access control in the Telegram legacy allowFrom migration logic when migrating default-account trust settings into named accounts. A remote user can rely on inherited trust relationships to bypass account trust boundaries.