CVE-2026-42438
7.7OpenClaw · OpenClaw
OpenClaw contains an incorrect authorization vulnerability in the outbound host-media attachment read helper, allowing unauthorized local file disclosure.
Executive summary
An incorrect authorization flaw in OpenClaw versions 2026.4.9 before 2026.4.10 allows authenticated attackers to bypass sender policy restrictions and retrieve arbitrary local files.
Vulnerability
This is an incorrect authorization vulnerability, classified under CWE-863, affecting the outbound host-media attachment read helper with low privileges required and network attack vector.
Business impact
A successful exploit allows unauthorized access to sensitive local files, potentially exposing internal system configurations or confidential data. With a CVSS score of 7.7, this high severity vulnerability threatens organizational confidentiality and demands prompt remediation to prevent data exfiltration.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.4.10 or later.
Proactive Monitoring: Review access logs and monitor for anomalous file read requests originating from the outbound media path.
Compensating Controls: Restrict network access to the affected service and enforce strict principle of least privilege regarding file system permissions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity rating and potential for local file disclosure, security teams should treat this advisory with urgency. Apply the official vendor update to version 2026.4.10 immediately to eliminate the authorization bypass vector and secure sensitive file assets.
More OpenClaw CVEs
Sources
Originally found and disclosed by Akiyama Mio (@Telecaster2147), per the CVE Program record.
- GitHub Security Advisory (GHSA-jhpv-5j76-m56h) Vendor advisory
- Patch Commit Patch commit
- VulnCheck Advisory: OpenClaw 2026.4.9 < 2026.4.10 - Sender Policy Bypass in Host Media Attachment Reads Third-party advisory