CVE-2026-35653
High Severity
Description
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.w...
Related Vulnerabilities
- CVE-2026-5466: wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the sig HIGH
- CVE-2026-6057: FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload A CRITICAL
- CVE-2026-6024: A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7W MEDIUM
- CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting HIGH
- CVE-2026-5988: A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the HIGH
Related Coverage
Threat Actors