CVE-2026-35649
Medium Severity
Description
OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty al...
Related Vulnerabilities
- CVE-2026-4432: The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist own HIGH
- CVE-2026-40069: bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts MEDIUM
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-5187: Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. MEDIUM
- CVE-2026-35595: Vikunja vulnerable to Privilege Escalation via Project Reparenting HIGH
Related Coverage
Threat Actors