Denial of Service Vulnerability in OpenClaw by OpenClaw Inc.
CVE-2026-41346
6.3MEDIUM
What is CVE-2026-41346?
The vulnerability within OpenClaw versions prior to 2026.3.31 results from improper enforcement of pending pairing-request caps. Instead of restricting these caps on a per-account basis, they are capped per channel file. This oversight enables remote attackers to flood the system with pairing requests from compromised accounts, effectively exhausting the pending window. As a result, legitimate accounts may be blocked from initiating new pairing challenges, leading to a Denial of Service that disrupts normal operational functions.
Affected Version(s)
OpenClaw 2026.2.26 < 2026.3.31
OpenClaw 2026.3.31
