OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRemoteViewer is disabled, allowing unauthorized access. Attackers can bypass access controls by sending proxied requests that are incorrectly identified as local loopback traffic, circumventing intended remote viewer restrictions.
Cite this page
CVE-2026-41403. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-41403
Use CWE-807, Openclaw vendor hub and Openclaw product page to widen CVE-2026-41403 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-42426, CVE-2026-42423 and CVE-2026-42422 for nearby disclosures in the same product family.