CVE-2026-41340

· NIST NVD ↗

OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named accounts. Attackers can exploit this trust propagation to bypass authentication controls and gain unauthorized access to named accounts.

MEDIUM
CVSS severity
6.5
CVSS base score
2026-04-23
Published

CWE codes

CWE-372

Affected products

openclaw:openclaw

Sources