CVE-2026-35669
High Severity
Description
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime ...
Related Vulnerabilities
- CVE-2026-35665: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook han MEDIUM
- CVE-2026-35648: OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not r LOW
- CVE-2026-40260: pypdf: Manipulated XMP metadata entity declarations can exhaust RAM MEDIUM
- CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , i MEDIUM
- CVE-2026-2305: The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM
Related Coverage
Threat Actors