CVE-2026-35657
High Severity
Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validatio...
Related Vulnerabilities
- CVE-2026-40225: In udev in systemd before 260, local root execution can occur via malicious hardware devices and uns MEDIUM
- CVE-2026-5984: A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of th HIGH
- CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` HIGH
- CVE-2026-23780: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in HIGH
- CVE-2026-29002: CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users t HIGH
Related Coverage
Threat Actors