CVE-2026-44116 - Vulnerability Analysis
HighCVSS: 8.6Last Updated: May 6, 2026
OpenClaw - Server Side Request Forgery
Published: May 6, 2026Updated: May 6, 2026Remote Exploitable
Overview
OpenClaw < 2026.4.22 contains a server-side request forgery caused by improper validation of outbound photo URLs in the Zalo plugin's sendPhoto function, letting attackers bypass SSRF protection and access internal resources.
Severity & Score
Severity: High
CVSS Score: 8.6
Impact
Attackers can access internal resources by bypassing SSRF protections, potentially leading to unauthorized data access or further network attacks.
Mitigation
Update to version 2026.4.22 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-44116
- Severity
- High
- CVSS Score
- 8.6
- Type
- server_side_request_forgery
- Status
- unconfirmed
CWE
- CWE-918
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N