Scope Enforcement Bypass in OpenClaw Media Access
CVE-2026-41908
2.3LOW
What is CVE-2026-41908?
OpenClaw prior to version 2026.4.20 contains a vulnerability in the assistant-media route that permits unauthorized access to sensitive media files and their metadata. Attackers leveraging trusted-proxy calls can bypass the scope validation normally governed by the identity-bearing HTTP authentication path, leading to potential exposure of private media content that should be protected.
Affected Version(s)
OpenClaw 0 < 2026.4.20
OpenClaw 2026.4.20
