PT-2026-31963 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35652

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description OpenClaw contains an authorization bypass in interactive callback dispatch. Non-allowlisted senders can execute action handlers by dispatching callbacks before security validation is complete, bypassing sender authorization checks. This allows unauthorized actions.
Recommendations Update to version 2026.3.22 or later.

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35652
GHSA-8883-9W57-VWV6

Affected Products

Openclaw