CVE-2026-35620
Medium Severity
Description
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner ...
Related Vulnerabilities
- CVE-2026-40224: In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink c MEDIUM
- CVE-2026-32932: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulne MEDIUM
- CVE-2026-23780: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in HIGH
- CVE-2026-5500: wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication t HIGH
- CVE-2026-40023: Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayou MEDIUM
Related Coverage
Threat Actors