CVE-2026-35661
Medium Severity
Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows attackers to mutate session state with...
Related Vulnerabilities
- CVE-2026-32146: Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows a MEDIUM
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
- CVE-2026-29146: Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This MEDIUM
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-6000: A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unkn MEDIUM
Related Coverage
Threat Actors