CVE-2026-35655
Medium Severity
Description
OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicting tool identity hints from rawInput an...
Related Vulnerabilities
- CVE-2026-34424: Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access to CRITICAL
- CVE-2026-40157: PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .pr CRITICAL
- CVE-2026-4895: The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cros MEDIUM
- CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout. MEDIUM
- CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas HIGH
Related Coverage
Threat Actors