Incorrect authorization in OpenClaw - CVE-2026-41350
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass session visibility restrictions.
The vulnerability exists due to incorrect authorization in the session_status functionality when handling unsandboxed invocations. A remote user can invoke session_status in an unsandboxed context to bypass session visibility restrictions.
This is a same-agent session-policy bypass rather than a broader host-boundary break.