Wide-Area Discovery Vulnerability in OpenClaw by OpenClaw Team
CVE-2026-41393

5.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41393?

OpenClaw versions prior to 2026.3.31 exhibit a flaw in their wide-area discovery mechanism, which permits unauthorized tailnet peers to be recognized as legitimate DNS authorities. This vulnerability could enable adversaries positioned on the same tailnet to manipulate DNS steering, leading to the unauthorized exfiltration of confidential operator credentials. Organizations using OpenClaw should evaluate their deployments and apply necessary patches to mitigate potential risks.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nathan (@nexrin)
KeenSecurityLab
qclawer
.