CVE-2026-35620
Medium Severity
Description
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner ...
Related Vulnerabilities
- CVE-2026-40188: goshs is Missing Write Protection for Parametric Data Values HIGH
- CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow MEDIUM
- CVE-2021-47961: A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows HIGH
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-35657: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sess HIGH
Related Coverage
Threat Actors