← Browse

CVE-2026-41371

Medium

Elevated severity or exploit probability.

CVSS base
8.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
EPSS — probability of exploitation (30 days)
0.3%
17.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-863
Published 2026-04-28 · modified 2026-07-24

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeCChanged
ConfidentialityNNone
IntegrityHHigh
AvailabilityLLow

Timeline

Description

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.

Affected

openclaw

References

Official: NVD · CVE.org