CVE-2026-35620
Medium Severity
Description
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner ...
Related Vulnerabilities
- CVE-2026-40156: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file name HIGH
- CVE-2026-35659: OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour MEDIUM
- CVE-2026-35595: Vikunja vulnerable to Privilege Escalation via Project Reparenting HIGH
- CVE-2026-5988: A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the HIGH
- CVE-2026-32892: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a CRITICAL
Related Coverage
Threat Actors