2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41354MEDIUM5.3OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows leg...
CVE-2026-41353HIGH8.1OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attac...
CVE-2026-41352HIGH8.8OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node ...
CVE-2026-41351MEDIUM6.3OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas...
CVE-2026-41350MEDIUM5.3OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to ...
CVE-2026-41349HIGH8.8OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu...
CVE-2026-41348MEDIUM5.4OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths...
CVE-2026-41347HIGH7.1OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mod...
CVE-2026-41346HIGH7.5OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allow...
CVE-2026-41345MEDIUM6OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut...
CVE-2026-41344HIGH8.8OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scop...
CVE-2026-41343MEDIUM6.9OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers...
CVE-2026-41342HIGH8.1OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persis...
CVE-2026-41341MEDIUM5.4OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direc...
CVE-2026-41340MEDIUM6.5OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration in...
CVE-2026-41339MEDIUM5.3OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin auth...
CVE-2026-41338MEDIUM5OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta...
CVE-2026-41337MEDIUM6.3OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac...
CVE-2026-41336HIGH8.5OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, e...
CVE-2026-41335MEDIUM6.9OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that ...
CVE-2026-41334HIGH7.1OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce...
CVE-2026-41333MEDIUM6.3OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumv...
CVE-2026-41332MEDIUM5.8OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON...
CVE-2026-41274CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher...
CVE-2026-35431CRITICAL10Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perfo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now