CVE-2026-35657
High Severity
Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validatio...
Related Vulnerabilities
- CVE-2026-35656: OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For hea MEDIUM
- CVE-2026-6015: A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of HIGH
- CVE-2026-35596: Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug MEDIUM
- CVE-2026-6005: A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is MEDIUM
- CVE-2026-35641: OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hoo HIGH
Related Coverage
Threat Actors