PT-2026-31760 · Openclaw+1 · Openclaw+1
Peng Zhou
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-35624
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
OpenClaw contains a policy confusion vulnerability in room authorization. The issue occurs because the software matches colliding room names instead of stable room tokens. This allows attackers to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms by exploiting similarly named rooms.
Recommendations
Update to version 2026.3.22 or later.
Fix
IDOR
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Talk
Openclaw