CVE-2026-35664
Medium Severity
Description
OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy callback payl...
Related Vulnerabilities
- CVE-2025-14545: The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via CRITICAL
- CVE-2026-4149: Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerabil CRITICAL
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-35596: Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug MEDIUM
- CVE-2026-33092: Local privilege escalation due to improper handling of environment variables. The following products HIGH
Related Coverage
Threat Actors