PT-2026-31966 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-35655
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
The software contains an identity spoofing issue in ACP permission resolution. The system incorrectly trusts conflicting tool identity hints from rawInput and metadata, potentially suppressing dangerous-tool prompting. Attackers can exploit this by spoofing tool identities through the
rawInput parameters, bypassing security restrictions.Recommendations
Update to version 2026.3.22 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw