CVE-2026-41300
Openclaw ≤ 2026.3.31
Raw vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2026-41300 is a medium-severity Incomplete Internal State Distinction (CWE-372) vulnerability in Openclaw Openclaw. Its CVSS base score is 6.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique External Remote Services (T1133); ranked at the 17th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to AC-17 (Remote Access) and AC-4 (Information Flow Enforcement) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-24008
Vulnerability Data
OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials to malicious endpoints by having their discovered URL survive the trust decline process into manual prompts requiring operator acceptance.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Vulnerability in remote onboarding trust handling directly enables acceptance of attacker-supplied malicious endpoints for credential routing, facilitating external remote service abuse and adversary-in-the-middle attacks.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly governs remote access onboarding flows and endpoint acceptance decisions that the CVE exploits to route credentials.
Enforces information flow rules so that discovered endpoints cannot be used to exfiltrate gateway credentials after trust decline.
Requires validation of externally supplied URLs/endpoints before they reach manual prompts or credential routing.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect state-machine flaws that manifest as incomplete internal state distinction.
Secure development lifecycle practices can include state-machine validation and invariant checks that reduce incomplete internal state errors.
Explicit application security requirements can mandate state-transition validation and error-state handling.
Secure architecture principles encourage explicit state modelling and fail-safe transitions.
Secure coding standards can require defensive checks against invalid or ambiguous internal states.
Change-management procedures may indirectly catch state-related defects during release reviews.