Improper Access Control in OpenClaw Affects Browser Snapshot Features
CVE-2026-42436
4.9MEDIUM
What is CVE-2026-42436?
OpenClaw versions prior to 2026.4.14 suffer from an improper access control vulnerability that affects browser snapshot and screenshot functionalities. This flaw allows authenticated users to bypass server-side request forgery (SSRF) restrictions by improperly navigating routes without adequate validation of the final browser target. As a result, sensitive internal or restricted page content may be unintentionally exposed, posing significant security risks. Immediate updates and patches are recommended to secure affected installations.
Affected Version(s)
OpenClaw 0 < 2026.4.14
OpenClaw 2026.4.14
