CVE-2026-41346
MEDIUMDescription
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the shared pending window. Remote attackers can submit pairing requests from other accounts to block new pairing challenges on unaffected accounts, causing denial of service.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openclaw | openclaw |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-41346? +
How severe is CVE-2026-41346? +
What products are affected by CVE-2026-41346? +
How do I check if I'm vulnerable to CVE-2026-41346? +
Related Vulnerabilities
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An …
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API …
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary …
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an …
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation …
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 …