CVE-2026-41298 is an authorization bypass vulnerability affecting OpenClaw versions prior to 2.026.4.2. The flaw exists in the POST /sessions/:sessionKey/kill endpoint, which fails to properly enforce write scope restrictions in identity-bearing HTTP modes, allowing read-scoped callers to terminate active subagent sessions without appropriate permissions. The vulnerability presents a medium severity risk with a CVSS score of 5.4. It can be exploited over the network by authenticated users with low complexity and no user interaction required. The impact includes partial loss of confidentiality and integrity, though availability is not directly affected. The EPSS score of 0.00025 indicates this vulnerability ranks higher than most CVEs in terms of exploitability probability. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the Known Exploited Vulnerabilities catalog, and community attention remains minimal with an inactive status on threat tracking lists. Organizations using OpenClaw should prioritize upgrading to version 2026.4.2 or later to remediate this authorization control bypass.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.4.2CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.4.2CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.