Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-42438

OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allows unauthorized local file disclosure. Attackers with denied read access via toolsBySender or group policy can trigger host-media attachment loading to bypass sender and group-scoped authorization boundaries and retrieve readable local files through the outbound media path.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.2%
CVSS Severity
CVSS v3 Score 7.7
Products affected by CVE-2026-42438
  • Openclaw » Openclaw » Version: 2026.4.9
    cpe:2.3:a:openclaw:openclaw:2026.4.9


Contact Us

Shodan ® - All rights reserved