CVE-2026-35669
High Severity
Description
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime ...
Related Vulnerabilities
- CVE-2026-39414: MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing HIGH
- CVE-2026-35661: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query MEDIUM
- CVE-2026-32252: Chartbrew is an open-source web application that can connect directly to databases and APIs and use HIGH
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a MEDIUM
Related Coverage
Threat Actors