PT-2026-31973 · Openclaw · Openclaw
Space08
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-35662
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
The issue involves a failure to enforce controlScope restrictions on the send action within OpenClaw. This allows leaf subagents to send messages to child sessions beyond their authorized scope, bypassing intended access control restrictions. The
send action does not properly validate scope, enabling unauthorized communication with child sessions. The fix involves threading controller context through the send path and blocking send attempts unless the requester owns the target and has controlScope set to 'children'.Recommendations
Update to version 2026.3.22 or later.
Fix
Missing Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw