CVE-2026-41366 — AppendLocalMediaParentRoots That Vulnerability

CVE-2026-41366 — AppendLocalMediaParentRoots That Vulnerability

CVE-2026-41366 — OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files

What This Means For You

  • If your environment is affected by CWE-732, review your exposure and prioritize patching based on your environment. Monitor vendor advisories for CVE-2026-41366 updates and patches.

Related ATT&CK Techniques

🛡️ Detection Rules

3 rules · 6 SIEM formats

3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.

high T1005 Collection

CVE-2026-41366 - OpenClaw appendLocalMediaParentRoots Arbitrary File Read

Sigma YAML — free preview
title: CVE-2026-41366 - OpenClaw appendLocalMediaParentRoots Arbitrary File Read
id: scw-2026-04-28-ai-1
status: experimental
level: high
description: |
  Detects the specific function call 'appendLocalMediaParentRoots' within OpenClaw.exe when combined with path traversal characters ('../') in the command line, indicating an attempt to exploit CVE-2026-41366 for arbitrary host file reads.
author: SCW Feed Engine (AI-generated)
date: 2026-04-28
references:
  - https://shimiscyberworld.com/posts/nvd-CVE-2026-41366/
tags:
  - attack.collection
  - attack.t1005
logsource:
    category: process_creation
detection:
  selection:
      Image|endswith:
          - 'OpenClaw.exe'
      CommandLine|contains:
          - 'appendLocalMediaParentRoots'
      CommandLine|contains:
          - '../'
      condition: Image AND CommandLine
falsepositives:
  - Legitimate administrative activity

Source: Shimi's Cyber World · License & reuse

✓ Sigma · Splunk SPL Sentinel KQL Elastic QRadar AQL Wazuh Get rules for your SIEM →

Indicators of Compromise

IDTypeIndicator
CVE-2026-41366 vulnerability CVE-2026-41366
CWE-732 weakness CWE-732
Source & Attribution
Source PlatformNVD
ChannelNational Vulnerability Database
PublishedApril 28, 2026 at 03:16 UTC

This content was curated and summarized by Shimi's Cyber World for informational purposes. It is not copied or republished in full. All intellectual property rights remain with the original author and source.

Believe this infringes your rights? Submit a takedown request.

Related coverage

CVE-2026-7218: Totolink N300RT Buffer Overflow Exploited Remotely

CVE-2026-7218 — A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so....

vulnerabilityCVEhigh-severitybuffer-overflowcwe-119cwe-120
/SCW Vulnerability Desk /HIGH /7.2 /⚑ 3 IOCs /⚙ 5 Sigma

CVE-2026-7217 — Deepractice PromptX Path Traversal

CVE-2026-7217 — A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-office/src/index.ts...

vulnerabilityCVEmedium-severitypath-traversalcwe-22cwe-36
/SCW Vulnerability Desk /MEDIUM /5.3 /⚑ 3 IOCs /⚙ 3 Sigma

CVE-2026-7216: donchelo processing-claude-mcp-bridge Path Traversal

CVE-2026-7216 — A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. Impacted is an unknown function of the file processing_server.py of the component...

vulnerabilityCVEhigh-severitypath-traversalcwe-22
/SCW Vulnerability Desk /HIGH /7.3 /⚑ 4 IOCs /⚙ 3 Sigma