Loading market data...
← Back to CVE feed

CVE-2026-35648

LOW CVSS 3.7 View on NVD ↗

Description

OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attackers can exploit stale allowlists or declarations that survive policy tightening to execute unauthorized commands.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Apr 10, 2026 17:17 UTC Modified: Apr 10, 2026 17:17 UTC