CVE-2026-35669
High Severity
Description
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime ...
Related Vulnerabilities
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-40226: In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted op MEDIUM
- CVE-2026-5226: The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
- CVE-2025-13926: An attacker could use data obtained by sniffing the network traffic to
forge packets in order to ma CRITICAL
- CVE-2026-35658: OpenClaw before 2026.3.2 contains a filesystem boundary bypass vulnerability in the image tool that MEDIUM
Related Coverage
Threat Actors