PT-2026-31973 · Openclaw · Openclaw

Space08

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35662

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description The issue involves a failure to enforce controlScope restrictions on the send action within OpenClaw. This allows leaf subagents to send messages to child sessions beyond their authorized scope, bypassing intended access control restrictions. The send action does not properly validate scope, enabling unauthorized communication with child sessions. The fix involves threading controller context through the send path and blocking send attempts unless the requester owns the target and has controlScope set to 'children'.
Recommendations Update to version 2026.3.22 or later.

Fix

Missing Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35662
GHSA-X2CM-HG9C-MF5W

Affected Products

Openclaw