CVE-2026-35666
High Severity
Description
OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers can bypass ex...
Related Vulnerabilities
- CVE-2026-1502: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. MEDIUM
- CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability al HIGH
- CVE-2026-5809: The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and HIGH
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-23781: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user cred CRITICAL
Related Coverage
Threat Actors