PT-2026-31757 · Openclaw+1 · Openclaw+1

Keensecuritylab

+1

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35618

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.23
Description OpenClaw contains a replay identity issue in Plivo V2 signature verification. This allows attackers to bypass replay protection by modifying query parameters. The verification process generates replay keys from the complete URL, including query strings, rather than a standardized base URL. This enables attackers to create new, verified request keys by making unsigned changes to query parameters in signed requests.
Recommendations Update to version 2026.3.23 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-35618
GHSA-CG6C-Q2HX-69H7
GHSA-J56C-WPQM-H24X

Affected Products

Openclaw
Plivo V2