PT-2026-31772 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35637

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description OpenClaw before version 2026.3.22 performs cite expansion before completing channel and direct message (DM) authorization checks. This allows cite work and content handling to occur before final authorization decisions, potentially enabling unauthorized access or manipulation of content.
Recommendations Update to version 2026.3.22 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35637
GHSA-P6J4-WVMC-VX2H
GHSA-VFG3-PQPQ-93M4

Affected Products

Openclaw