2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41396 | HIGH | 7.8 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable,... |
| CVE-2026-41395 | HIGH | 8.2 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes ... |
| CVE-2026-41394 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes ... |
| CVE-2026-41393 | MEDIUM | 4.8 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted a... |
| CVE-2026-41392 | HIGH | 7.3 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust ... |
| CVE-2026-41391 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execut... |
| CVE-2026-41390 | HIGH | 7.3 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap... |
| CVE-2026-41388 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s... |
| CVE-2026-41387 | HIGH | 8.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-securi... |
| CVE-2026-41386 | CRITICAL | 9.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to int... |
| CVE-2026-41385 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me... |
| CVE-2026-41384 | HIGH | 8.5 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows... |
| CVE-2026-41383 | HIGH | 8.1 | 0.4% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to ... |
| CVE-2026-41382 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers ... |
| CVE-2026-41381 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac... |
| CVE-2026-41380 | HIGH | 7.3 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-... |
| CVE-2026-41379 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm... |
| CVE-2026-41378 | HIGH | 8.8 | 0.4% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch... |
| CVE-2026-41377 | MEDIUM | 5.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure... |
| CVE-2026-41376 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th... |
| CVE-2026-41375 | HIGH | 7.1 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t... |
| CVE-2026-41374 | MEDIUM | 6.9 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin... |
| CVE-2026-41373 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary en... |
| CVE-2026-3893 | CRITICAL | 9.4 | 0.4% | Apr 28, 2026 | The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to direct... |
| CVE-2026-38949 | HIGH | 8.9 | 0.4% | Apr 28, 2026 | Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now