CVE-2026-35655
Medium Severity
Description
OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicting tool identity hints from rawInput an...
Related Vulnerabilities
- CVE-2026-5984: A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of th HIGH
- CVE-2026-6035: A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected MEDIUM
- CVE-2026-35641: OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hoo HIGH
- CVE-2026-40069: bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts MEDIUM
- CVE-2025-62718: Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF MEDIUM
Related Coverage
Threat Actors