CVE-2026-35662
Medium Severity
Description
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond th...
Related Vulnerabilities
- CVE-2026-5496: Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability HIGH
- CVE-2026-35620: OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist MEDIUM
- CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she HIGH
- CVE-2026-5778: Integer underflow in wolfSSL packet sniffer LOW
- CVE-2026-5466: wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the sig HIGH
Related Coverage
Threat Actors