CVE-2026-35619
Medium Severity
Description
OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements...
Related Vulnerabilities
- CVE-2026-32892: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a CRITICAL
- CVE-2026-4057: The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to MEDIUM
- CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v MEDIUM
- CVE-2026-40154: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched templat CRITICAL
- CVE-2026-40226: In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted op MEDIUM
Related Coverage
Threat Actors