CVE-2026-35653
High Severity
Description
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.w...
Related Vulnerabilities
- CVE-2026-34988: Wasmtime has data leakage between pooling allocator instances MEDIUM
- CVE-2026-40180: Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs gen N/A
- CVE-2026-34983: Wasmtime has use-after-free bug after cloning `wasmtime::Linker` MEDIUM
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-35599: Vikunja has Algorithmic Complexity DoS in Repeating Task Handler MEDIUM
Related Coverage
Threat Actors