CVE-2026-35661
Medium Severity
Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows attackers to mutate session state with...
Related Vulnerabilities
- CVE-2026-5809: The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and HIGH
- CVE-2026-31941: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a HIGH
- CVE-2026-6012: A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSet HIGH
- CVE-2026-33141: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Referenc MEDIUM
- CVE-2026-34727: Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path HIGH
Related Coverage
Threat Actors