Authorization Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-35642

5.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-35642?

An authorization bypass vulnerability exists in OpenClaw prior to version 2026.3.25 that affects the requireMention access control mechanism. This flaw allows attackers to execute reactions in groups that are gated by mentions, leading to the creation of agent-visible system events that should otherwise be restricted. The vulnerability can compromise the intended access controls, allowing unauthorized interactions within the application.

Affected Version(s)

OpenClaw 0 < 2026.3.25

OpenClaw 2026.3.25

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou (@zpbrent)
.