CVE-2026-35657
High Severity
Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validatio...
Related Vulnerabilities
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
- CVE-2026-40223: In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and U MEDIUM
- CVE-2026-4152: GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi HIGH
- CVE-2026-5992: A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of HIGH
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 HIGH
Related Coverage
Threat Actors