2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41396HIGH7.8OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable,...
CVE-2026-41395HIGH8.2OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes ...
CVE-2026-41394HIGH8.8OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes ...
CVE-2026-41393MEDIUM4.8OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted a...
CVE-2026-41392HIGH7.3OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust ...
CVE-2026-41391MEDIUM6.1OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execut...
CVE-2026-41390HIGH7.3OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap...
CVE-2026-41388MEDIUM6.5OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s...
CVE-2026-41387HIGH8.5OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-securi...
CVE-2026-41386CRITICAL9.8OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to int...
CVE-2026-41385HIGH7.1OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me...
CVE-2026-41384HIGH8.5OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows...
CVE-2026-41383HIGH8.1OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to ...
CVE-2026-41382MEDIUM5.4OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers ...
CVE-2026-41381MEDIUM5.4OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac...
CVE-2026-41380HIGH7.3OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-...
CVE-2026-41379HIGH7.1OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm...
CVE-2026-41378HIGH8.8OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch...
CVE-2026-41377MEDIUM5.1OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure...
CVE-2026-41376MEDIUM6.5OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th...
CVE-2026-41375HIGH7.1OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t...
CVE-2026-41374MEDIUM6.9OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin...
CVE-2026-41373MEDIUM6.1OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary en...
CVE-2026-3893CRITICAL9.4The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to direct...
CVE-2026-38949HIGH8.9Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now