CVE-2026-35620
Medium Severity
Description
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner ...
Related Vulnerabilities
- CVE-2026-35650: OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allo HIGH
- CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability al HIGH
- CVE-2026-5995: A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function se CRITICAL
- CVE-2026-4156: ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. HIGH
- CVE-2026-35577: Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. P MEDIUM
Related Coverage
Threat Actors