Missing Authorization Vulnerability in OpenClaw by OpenClaw
CVE-2026-35620
5.3MEDIUM
What is CVE-2026-35620?
OpenClaw versions before 2026.3.24 are susceptible to a missing authorization flaw in the /send and /allowlist command handlers. Attackers possessing operator.write privileges can invoke the /send command to alter delivery policy settings, while the /allowlist commands enable them to modify critical configuration entries without sufficient admin rights. This vulnerability undermines the application’s security mechanisms, potentially allowing unauthorized users to manipulate session settings and access control lists.
Affected Version(s)
OpenClaw 0 < 2026.3.24
OpenClaw 2026.3.24
