CVE-2026-41353
8.1OpenClaw · OpenClaw
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature, allowing authenticated attackers to manipulate browser proxy profiles and bypass security restrictions.
Executive summary
A critical access control bypass vulnerability in OpenClaw allows authenticated attackers to manipulate profile settings and circumvent security restrictions, posing a significant risk to organizational policy enforcement.
Vulnerability
The software contains an access control bypass flaw stemming from the improper handling of immutable web parameters. An authenticated attacker can exploit this by performing persistent profile mutation and runtime profile selection to access restricted browser proxy configurations.
Business impact
The ability to bypass intended access controls undermines the integrity of organizational security policies regarding network traffic and proxy usage. Successful exploitation could lead to unauthorized data exfiltration or access to restricted internal resources, potentially violating compliance requirements. Given the CVSS score of 8.1, this vulnerability represents a high-severity risk that could facilitate further unauthorized actions within the network environment.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.3.22 or later to resolve the underlying access control logic error.
Proactive Monitoring: Monitor application and proxy logs for unusual profile mutation activity or unauthorized attempts to access restricted proxy configurations during runtime.
Compensating Controls: Implement strict network-level egress filtering to restrict unauthorized proxy traffic if immediate patching is not possible.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to internal security controls and requires immediate attention. IT administrators should prioritize the deployment of version 2026.3.22 across all affected instances to eliminate the possibility of unauthorized profile manipulation. Failure to patch may result in the degradation of network security posture and potential unauthorized access to restricted segments.
More OpenClaw CVEs
Sources
Originally found and disclosed by smaeljaish771, KeenSecurityLab, per the CVE Program record.
- GitHub Security Advisory (GHSA-h5hg-h7rr-gpf3) Vendor advisory
- Patch Commit Patch commit
- VulnCheck Advisory: OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection Third-party advisory