HIGH
OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection
Published Apr 23, 2026
7.6
HIGHCVSS 4.0
EPSS 0.61%
Description
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.22
- Version 2026.3.22StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.22 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/openclaw/openclaw/commit/eac93507c36ccd0c359fba18fa466ef6448be8a5 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-h5hg-h7rr-gpf3 vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-allowprofiles-bypass-via-profile-mutation-and-runtime-selection third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/openclaw/openclaw/commit/eac93507c36ccd0c359fba18fa466ef6448be8a5 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-h5hg-h7rr-gpf3 | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-allowprofiles-bypass-via-profile-mutation-and-runtime-selection | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 25, 2026
Reserved Apr 20, 2026
Link CVE-2026-41353
CISA Vulnrichment
Updated Apr 25, 2026