Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-35631

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Apr 09, 2026
Vendor unknown

Description

OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking affected ACP commands to bypass authorization gates.

References