PT-2026-31770 · Openclaw+1 · Openclaw+1
Tdjackey
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-35635
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
OpenClaw before version 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension. This allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account direct message access control policies and replace route ownership across accounts.
Recommendations
Update OpenClaw to version 2026.3.22 or later.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw
Synology Chat