Missing Authorization Vulnerability in OpenClaw by OpenClaw
CVE-2026-35620

5.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-35620?

OpenClaw versions before 2026.3.24 are susceptible to a missing authorization flaw in the /send and /allowlist command handlers. Attackers possessing operator.write privileges can invoke the /send command to alter delivery policy settings, while the /allowlist commands enable them to modify critical configuration entries without sufficient admin rights. This vulnerability undermines the application’s security mechanisms, potentially allowing unauthorized users to manipulate session settings and access control lists.

Affected Version(s)

OpenClaw 0 < 2026.3.24

OpenClaw 2026.3.24

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tdjackey
.