CVE-2026-35669
High Severity
Description
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime ...
Related Vulnerabilities
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-40191: ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. N/A
- CVE-2026-5772: A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) duri LOW
- CVE-2026-5774: Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, an MEDIUM
- CVE-2026-40156: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file name HIGH
Related Coverage
Threat Actors