PT-2026-38238 · Openclaw · Openclaw

·

CVE-2026-43583

·

Published

2026-04-17

·

Updated

2026-05-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.10 through 2026.4.13
Description An issue exists where session context is not persisted during delivery queue recovery for media replay. This allows attackers to exploit recovered queued outbound media to bypass group tool policy enforcement and weaken channel media restrictions following a service restart or recovery.
Recommendations Update to version 2026.4.14.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43583
GHSA-82RM-QCFX-2V78
GHSA-R77C-2CMR-7P47

Affected Products

Openclaw