CVE-2026-41382

· NIST NVD ↗

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member allowlist restrictions. Attackers can exploit stale-role validation gaps and improper channel name validation to gain unauthorized access to restricted voice channels.

MEDIUM
CVSS severity
5.4
CVSS base score
2026-04-28
Published

CWE codes

CWE-862

Affected products

openclaw:openclaw

Sources