Remote Code Execution Vulnerability in OpenClaw by OpenClaw
CVE-2026-41352
7.7HIGH
What is CVE-2026-41352?
OpenClaw versions prior to 2026.3.31 have a vulnerability that allows a device-paired node to bypass authentication mechanisms, potentially enabling attackers with device pairing credentials to execute arbitrary commands on the host system without validation. This flaw represents a significant risk as it can lead to unauthorized access and control over the affected devices.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
