CVE-2026-35660
High Severity
Description
OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that allows callers with operator.write perm...
Related Vulnerabilities
- CVE-2026-40259: SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttribut HIGH
- CVE-2026-6024: A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7W MEDIUM
- CVE-2026-35650: OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allo HIGH
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2026-33710: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are gene HIGH
Related Coverage
Threat Actors