Incorrect Authorization Vulnerability in OpenClaw Product by OpenClaw
CVE-2026-35653
7.2HIGH
What is CVE-2026-35653?
OpenClaw prior to version 2026.3.24 has a vulnerability that allows authenticated users with operator.write access to the browser.request surface to exploit profile mutation controls. This flaw is found in the POST /reset-profile endpoint, enabling attackers to stop the running browser, terminate Playwright connections, and transfer profile directories to Trash, thereby circumventing the intended access restrictions.
Affected Version(s)
OpenClaw 0 < 2026.3.24
OpenClaw 2026.3.24
