PT-2026-31770 · Openclaw+1 · Openclaw+1

Tdjackey

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35635

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description OpenClaw before version 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension. This allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account direct message access control policies and replace route ownership across accounts.
Recommendations Update OpenClaw to version 2026.3.22 or later.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35635
GHSA-G8MC-C5F2-MQG7
GHSA-RQP8-Q22P-5J9Q

Affected Products

Openclaw
Synology Chat