CVE-2026-42438

7.7

OpenClaw · OpenClaw

OpenClaw contains an incorrect authorization vulnerability in the outbound host-media attachment read helper, allowing unauthorized local file disclosure.

Executive summary

An incorrect authorization flaw in OpenClaw versions 2026.4.9 before 2026.4.10 allows authenticated attackers to bypass sender policy restrictions and retrieve arbitrary local files.

Vulnerability

This is an incorrect authorization vulnerability, classified under CWE-863, affecting the outbound host-media attachment read helper with low privileges required and network attack vector.

Business impact

A successful exploit allows unauthorized access to sensitive local files, potentially exposing internal system configurations or confidential data. With a CVSS score of 7.7, this high severity vulnerability threatens organizational confidentiality and demands prompt remediation to prevent data exfiltration.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.4.10 or later.

Proactive Monitoring: Review access logs and monitor for anomalous file read requests originating from the outbound media path.

Compensating Controls: Restrict network access to the affected service and enforce strict principle of least privilege regarding file system permissions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity rating and potential for local file disclosure, security teams should treat this advisory with urgency. Apply the official vendor update to version 2026.4.10 immediately to eliminate the authorization bypass vector and secure sensitive file assets.

More OpenClaw CVEs

Sources

Originally found and disclosed by Akiyama Mio (@Telecaster2147), per the CVE Program record.