CVE-2026-41349: OpenClaw agentic consent bypass via config.patch
OpenClaw versions before 2026.3.28 contain a vulnerability that lets LLM agents silently disable execution approval through the config.patch parameter. Remote attackers can abuse this to bypass security controls and run unauthorized operations without user consent.
Disclosed 23 April 2026 · Record updated 13 September 2026
Impact
Allows bypass of execution approval controls, enabling unauthorized operations to be executed without user consent.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41349
