Timing Vulnerability in OpenClaw Affects Authorization Processes
CVE-2026-35637

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-35637?

Prior to the release of version 2026.3.22, OpenClaw exhibits a timing vulnerability where cite expansion is performed before completing authorization checks for channels and direct messages (DMs). This allows unauthorized access to manipulate and handle content during the interim period when the authorization has not yet been validated. Attackers can exploit this flaw, leading to potential unauthorized disclosures or modifications of sensitive information.

Affected Version(s)

OpenClaw 0 < 2026.3.22

OpenClaw 2026.3.22

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou (@zpbrent)
.