OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send verification notices to users outside allowed direct message policies by exploiting insufficient access validation before message transmission.
References
Configurations
History
No history.
Information
Published : 2026-04-10 17:17
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35647
Mitre link : CVE-2026-35647
CVE.ORG link : CVE-2026-35647
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
