CVE-2026-35669
High Severity
Description
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime ...
Related Vulnerabilities
- CVE-2026-23900: Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0 MEDIUM
- CVE-2026-5477: An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge C HIGH
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-40162: Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability wa HIGH
- CVE-2026-33737: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use sim MEDIUM
Related Coverage
Threat Actors