Access Control Vulnerability in OpenClaw Messaging Platform
CVE-2026-35647
6.9MEDIUM
What is CVE-2026-35647?
OpenClaw versions before 2026.3.25 exhibit an access control vulnerability that allows attackers to exploit insufficient validation of access rights. Specifically, this vulnerability enables verification notices to bypass direct message policies, allowing unauthorized users to send messages to others outside the defined communication boundaries. This poses a significant risk as it undermines the integrity of user interactions within the platform and can lead to potential information leakage or unauthorized access to sensitive communications.
Affected Version(s)
OpenClaw 0 < 2026.3.25
OpenClaw 2026.3.25
