LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-44116

CVE-2026-44116 - Vulnerability Analysis

HighCVSS: 8.6

Last Updated: May 6, 2026

OpenClaw - Server Side Request Forgery

Published: May 6, 2026Updated: May 6, 2026Remote Exploitable

Overview

OpenClaw < 2026.4.22 contains a server-side request forgery caused by improper validation of outbound photo URLs in the Zalo plugin's sendPhoto function, letting attackers bypass SSRF protection and access internal resources.

Severity & Score

Severity: High
CVSS Score: 8.6

Impact

Attackers can access internal resources by bypassing SSRF protections, potentially leading to unauthorized data access or further network attacks.

Mitigation

Update to version 2026.4.22 or later.

Details

CVE ID
CVE-2026-44116
Severity
High
CVSS Score
8.6
Type
server_side_request_forgery
Status
unconfirmed

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N