CVE-2026-41367
MEDIUM
NVD
CVSS Score
5
Severity
MEDIUM
Published
Apr 28, 2026
Vendor
unknown
Description
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.