Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-41378

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Apr 28, 2026
Vendor unknown

Description

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.

References