Session Context Persistence Issue in OpenClaw Media Replay
CVE-2026-43583

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-43583?

OpenClaw versions 2026.4.10 and earlier before 2026.4.14 are susceptible to a flaw that compromises session context during media replay recovery. This vulnerability allows attackers to exploit the delivery queue, enabling them to bypass the enforcement of group tool policies and undermining restrictions that govern channel media post-service restart or recovery. Consequently, this may lead to unauthorized access or manipulation of media content within affected systems.

Affected Version(s)

OpenClaw 2026.4.10 < 2026.4.14

OpenClaw 2026.4.14

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
qclawer
.