2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42427 | MEDIUM | 5.8 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist ... |
| CVE-2026-42426 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts ope... |
| CVE-2026-42424 | MEDIUM | 5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channe... |
| CVE-2026-42423 | HIGH | 7.7 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approva... |
| CVE-2026-42422 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting to... |
| CVE-2026-42421 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared ga... |
| CVE-2026-42420 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing... |
| CVE-2026-41916 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure become... |
| CVE-2026-41915 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host e... |
| CVE-2026-41914 | HIGH | 8.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass... |
| CVE-2026-41913 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent ... |
| CVE-2026-41912 | HIGH | 7.6 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigge... |
| CVE-2026-41911 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local f... |
| CVE-2026-41910 | MEDIUM | 4.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An ... |
| CVE-2026-41408 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limi... |
| CVE-2026-41407 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use ea... |
| CVE-2026-41406 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restri... |
| CVE-2026-41405 | HIGH | 8.7 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthentica... |
| CVE-2026-41404 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that ... |
| CVE-2026-41403 | MEDIUM | 4 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRe... |
| CVE-2026-41402 | MEDIUM | 5.4 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authen... |
| CVE-2026-41400 | HIGH | 7.5 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebS... |
| CVE-2026-41399 | HIGH | 8.7 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication bud... |
| CVE-2026-41398 | MEDIUM | 4.6 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic lo... |
| CVE-2026-41397 | CRITICAL | 9.6 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now