Loading market data...
← Back to CVE feed

CVE-2026-35647

MEDIUM CVSS 5.3 View on NVD ↗

Description

OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send verification notices to users outside allowed direct message policies by exploiting insufficient access validation before message transmission.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Apr 10, 2026 17:17 UTC Modified: Apr 10, 2026 17:17 UTC