CVE-2026-35657
High Severity
Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validatio...
Related Vulnerabilities
- CVE-2026-1502: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. MEDIUM
- CVE-2026-35665: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook han MEDIUM
- CVE-2026-5501: wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the HIGH
- CVE-2026-40227: In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with MEDIUM
- CVE-2026-5984: A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of th HIGH
Related Coverage
Threat Actors