CVE-2026-35662
Medium Severity
Description
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond th...
Related Vulnerabilities
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-40194: phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_ LOW
- CVE-2026-33092: Local privilege escalation due to improper handling of environment variables. The following products HIGH
- CVE-2026-6069: NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, HIGH
- CVE-2025-13926: An attacker could use data obtained by sniffing the network traffic to
forge packets in order to ma CRITICAL
Related Coverage
Threat Actors