CVE-2026-35653
High Severity
Description
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.w...
Related Vulnerabilities
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-40175: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain CRITICAL
- CVE-2026-1115: A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/l CRITICAL
- CVE-2026-35663: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators HIGH
- CVE-2026-32893: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ( MEDIUM
Related Coverage
Threat Actors