CVE-2026-41349: OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this t...
Added to the CISA Known Exploited Vulnerabilities catalog on 23 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent.
Required action: Review and patch if applicable to your AI infrastructure.