Improper privilege management in OpenClaw - CVE-2026-41359
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify admin-class Telegram configuration and establish cron persistence.
The vulnerability exists due to improper privilege management in the send functionality when handling authenticated send operations. A remote user can invoke the send sink to modify admin-class Telegram configuration and establish cron persistence.
This is a narrow, authenticated, sink-specific privilege escalation issue.