CVE-2026-35662
Medium Severity
Description
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond th...
Related Vulnerabilities
- CVE-2026-32892: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a CRITICAL
- CVE-2026-40089: Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audi CRITICAL
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-5975: A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the CRITICAL
- CVE-2025-58920: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i HIGH
Related Coverage
Threat Actors