Authorization Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-35642
5.3MEDIUM
What is CVE-2026-35642?
An authorization bypass vulnerability exists in OpenClaw prior to version 2026.3.25 that affects the requireMention access control mechanism. This flaw allows attackers to execute reactions in groups that are gated by mentions, leading to the creation of agent-visible system events that should otherwise be restricted. The vulnerability can compromise the intended access controls, allowing unauthorized interactions within the application.
Affected Version(s)
OpenClaw 0 < 2026.3.25
OpenClaw 2026.3.25
