CVE-2026-35649
Medium Severity
Description
OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty al...
Related Vulnerabilities
- CVE-2026-29861: PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the use CRITICAL
- CVE-2026-35597: Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout MEDIUM
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-34941: Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding MEDIUM
- CVE-2026-33737: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use sim MEDIUM
Related Coverage
Threat Actors