Status: UPDATED | Advisory ID: CVE-2026-41380
| CVE | CVE-2026-41380 |
| CVSS Score / Version | 7.3 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | openclaw openclaw |
| Classified as | CWE-807 (Reliance on Untrusted Inputs in a Security Decision) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| openclaw | openclaw |
| Subsystems | General OT |
| Sectors | Multiple |
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries. (NVD)
Monitor openclaw's web page for any future patch releases. See vendor advisory link below.