CVE-2026-35648
Low Severity
Description
OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Atta...
Related Vulnerabilities
- CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a MEDIUM
- CVE-2026-6012: A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSet HIGH
- CVE-2026-40228: In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users LOW
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
- CVE-2026-6029: A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the f CRITICAL
Related Coverage
Threat Actors