CVE-2026-35662
Medium Severity
Description
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond th...
Related Vulnerabilities
- CVE-2026-3690: OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to b HIGH
- CVE-2026-4157: ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vul HIGH
- CVE-2026-34944: Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 MEDIUM
- CVE-2026-33704: Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including stu HIGH
- CVE-2026-40258: gramps-webapi: Zip Slip Path Traversal in Media Archive Import CRITICAL
Related Coverage
Threat Actors