2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41354 | MEDIUM | 5.3 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows leg... |
| CVE-2026-41353 | HIGH | 8.1 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attac... |
| CVE-2026-41352 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node ... |
| CVE-2026-41351 | MEDIUM | 6.3 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas... |
| CVE-2026-41350 | MEDIUM | 5.3 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to ... |
| CVE-2026-41349 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu... |
| CVE-2026-41348 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths... |
| CVE-2026-41347 | HIGH | 7.1 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mod... |
| CVE-2026-41346 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allow... |
| CVE-2026-41345 | MEDIUM | 6 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut... |
| CVE-2026-41344 | HIGH | 8.8 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scop... |
| CVE-2026-41343 | MEDIUM | 6.9 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers... |
| CVE-2026-41342 | HIGH | 8.1 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persis... |
| CVE-2026-41341 | MEDIUM | 5.4 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direc... |
| CVE-2026-41340 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration in... |
| CVE-2026-41339 | MEDIUM | 5.3 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin auth... |
| CVE-2026-41338 | MEDIUM | 5 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta... |
| CVE-2026-41337 | MEDIUM | 6.3 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac... |
| CVE-2026-41336 | HIGH | 8.5 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, e... |
| CVE-2026-41335 | MEDIUM | 6.9 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that ... |
| CVE-2026-41334 | HIGH | 7.1 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce... |
| CVE-2026-41333 | MEDIUM | 6.3 | 0.4% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumv... |
| CVE-2026-41332 | MEDIUM | 5.8 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON... |
| CVE-2026-41274 | CRITICAL | 9.8 | 0.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher... |
| CVE-2026-35431 | CRITICAL | 10 | 0.5% | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perfo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now