PT-2026-31760 · Openclaw+1 · Openclaw+1

Peng Zhou

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35624

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description OpenClaw contains a policy confusion vulnerability in room authorization. The issue occurs because the software matches colliding room names instead of stable room tokens. This allows attackers to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms by exploiting similarly named rooms.
Recommendations Update to version 2026.3.22 or later.

Fix

IDOR

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35624
GHSA-5F7H-P83X-5VC2
GHSA-XHQ5-45PM-2GJR

Affected Products

Nextcloud Talk
Openclaw