Medium severity6.5GHSA Advisory· Published May 5, 2026· Updated May 5, 2026
CVE-2026-42433
CVE-2026-42433
Description
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate persistent profile configuration through non-owner message-tool runs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.4.10 | 2026.4.10 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-7jp6-r74r-995qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-42433ghsaADVISORY
- github.com/openclaw/openclaw/commit/fe0f686c9228fffcec6de4011da45e69a6e23e54nvdWEB
- github.com/openclaw/openclaw/pull/62662ghsaWEB
- github.com/openclaw/openclaw/security/advisories/GHSA-7jp6-r74r-995qnvdWEB
- www.vulncheck.com/advisories/openclaw-unauthorized-matrix-profile-config-persistence-access-via-operator-write-message-toolsnvdWEB
News mentions
0No linked articles in our index yet.