CVE-2026-35666 - OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper
CVE ID :CVE-2026-35666
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that f...
Related Vulnerabilities
- CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can HIGH
- CVE-2026-39315: Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe() MEDIUM
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2026-35662: OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing le MEDIUM
Related Coverage
Threat Actors