CVE-2026-35649
Medium Severity
Description
OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty al...
Related Vulnerabilities
- CVE-2026-35594: Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrad MEDIUM
- CVE-2026-40156: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file name HIGH
- CVE-2021-47960: A files or directories accessible to external parties vulnerability in Synology SSL VPN Client befor MEDIUM
- CVE-2026-35657: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sess HIGH
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
Related Coverage
Threat Actors