Authorization Bypass Vulnerability in Discord Voice Ingress of OpenClaw
CVE-2026-41382
2.3LOW
What is CVE-2026-41382?
OpenClaw versions prior to 2026.3.31 suffer from an authorization bypass flaw affecting the Discord voice ingress feature. This vulnerability allows attackers to circumvent channel and member allowlist restrictions, potentially leading to unauthorized access to restricted voice channels. The exploitation is possible due to gaps in stale-role validation and improper validation of channel names, enabling attackers to join or manipulate voice channels illegitimately.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
