๐Ÿ” CVE Alert

CVE-2026-35620

MEDIUM 5.4

OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
13th

OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command-authorized senders to change owner-only session delivery policy settings, and the /allowlist mutating commands fail to enforce operator.admin scope. Attackers with operator.write scope can invoke /send on|off|inherit to persistently mutate the current session's sendPolicy, and execute /allowlist add commands to modify config-backed allowFrom entries and pairing-store allowlist entries without proper admin authorization.

CWE CWE-862
Vendor openclaw
Product openclaw
Published Apr 10, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw

Be the first to know when new medium vulnerabilities affecting openclaw openclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

OpenClaw / OpenClaw
0 < 2026.3.24

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-39mp-545q-w789 github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-vqvg-86cc-cg83 github.com: https://github.com/openclaw/openclaw/commit/ccfeecb6887cd97937e33a71877ad512741e82b2 github.com: https://github.com/openclaw/openclaw/commit/ea018a68ccb92dbc735bc1df9880d5c95c63ca35 github.com: https://github.com/openclaw/openclaw/commit/555b2578a8cc6e1b93f717496935ead97bfbed8b vulncheck.com: https://www.vulncheck.com/advisories/openclaw-missing-authorization-in-send-and-allowlist-chat-commands

Credits

๐Ÿ” tdjackey