Description
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 23 Apr 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls. | |
| Title | OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-472 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-23T21:58:13.070Z
Reserved: 2026-04-20T14:07:26.648Z
Link: CVE-2026-41353
No data.
Status : Received
Published: 2026-04-23T22:16:42.493
Modified: 2026-04-23T22:16:42.493
Link: CVE-2026-41353
No data.
OpenCVE Enrichment
No data.
Weaknesses