Access Control Vulnerability in OpenClaw Messaging Platform
CVE-2026-35647

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-35647?

OpenClaw versions before 2026.3.25 exhibit an access control vulnerability that allows attackers to exploit insufficient validation of access rights. Specifically, this vulnerability enables verification notices to bypass direct message policies, allowing unauthorized users to send messages to others outside the defined communication boundaries. This poses a significant risk as it undermines the integrity of user interactions within the platform and can lead to potential information leakage or unauthorized access to sensitive communications.

Affected Version(s)

OpenClaw 0 < 2026.3.25

OpenClaw 2026.3.25

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou (@zpbrent)
.