HIGH
OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch
Published Apr 23, 2026
8.7
HIGHCVSS 4.0
EPSS 0.84%
Description
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.28
- Version 2026.3.28StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.28 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25333 Advisory
- https://github.com/openclaw/openclaw/commit/76411b2afc4ae721e36c12e0ea24fd23e2fed61e patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-v3qc-wrwx-j3pw vendor-advisoryPatchVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-agentic-consent-bypass-via-config-patch third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25333 | Advisory | |
| https://github.com/openclaw/openclaw/commit/76411b2afc4ae721e36c12e0ea24fd23e2fed61e | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-v3qc-wrwx-j3pw | vendor-advisoryPatchVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-agentic-consent-bypass-via-config-patch | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 20, 2026
Link CVE-2026-41349
CISA Vulnrichment
Updated Apr 24, 2026
ENISA EUVD
EUVD-2026-25333 Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Exploited since n/a
Link EUVD-2026-25333