← Zuruck zu CVEs
CVE-2026-41378
HIGH8.8
Beschreibung
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht4/28/2026
Zuletzt geandert5/1/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
openclaw:openclaw
Schwachen (CWE)
CWE-862
Referenzen
https://github.com/openclaw/openclaw/commit/a77928b1087e90f2a8903f8e5aca6dec9237ac62(disclosure@vulncheck.com)
https://github.com/openclaw/openclaw/security/advisories/GHSA-gjm7-hw8f-73rq(disclosure@vulncheck.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.