Improper access control in OpenClaw - CVE-2026-41353
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass profile restrictions.
The vulnerability exists due to improper access control in the node browser proxy allowProfiles mechanism when selecting profiles at runtime after persistent profile mutation. A remote user can modify profile state and select a runtime profile to bypass profile restrictions.