PT-2026-31959 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-27

·

Updated

2026-04-10

·

CVE-2026-35647

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.25
Description OpenClaw contains an access control issue where verification notices bypass direct message (DM) policy checks and can be sent to unpaired peers. Insufficient access validation before message transmission allows attackers to send verification notices to users outside of allowed DM policies.
Recommendations Update to version 2026.3.25 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35647
GHSA-9WQX-G2CW-VC7R

Affected Products

Openclaw