CVE-2026-35631

Source
https://cve.org/CVERecord?id=CVE-2026-35631
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35631.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-35631
Aliases
Downstream
Published
2026-04-09T21:27:01.899Z
Modified
2026-07-15T01:48:58.724145798Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands
Details

OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking affected ACP commands to bypass authorization gates.

Database specific
{
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35631.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/openclaw/openclaw

Affected ranges

Type
GIT
Repo
https://github.com/openclaw/openclaw
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2026.3.22"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v1.*
v1.0.4
v1.1.0
v1.2.0
v1.2.1
v1.2.2
v1.3.0
v2.*
v2.0.0-beta1
v2.0.0-beta2
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-beta5
v2026.*
v2026.1.10
v2026.1.11
v2026.1.11-1
v2026.1.11-2
v2026.1.11-3
v2026.1.12
v2026.1.12-2
v2026.1.13
v2026.1.14-1
v2026.1.15
v2026.1.16-2
v2026.1.20
v2026.1.21
v2026.1.22
v2026.1.23
v2026.1.24
v2026.1.24-1
v2026.1.29
v2026.1.30
v2026.1.5
v2026.1.5-1
v2026.1.5-2
v2026.1.5-3
v2026.1.8
v2026.1.9
v2026.2.1
v2026.2.12
v2026.2.13
v2026.2.14
v2026.2.15-beta.1
v2026.2.17
v2026.2.19
v2026.2.19-beta.1
v2026.2.2
v2026.2.21
v2026.2.21-beta.1
v2026.2.22
v2026.2.22-beta.1
v2026.2.23
v2026.2.23-beta.1
v2026.2.24
v2026.2.24-beta.1
v2026.2.25
v2026.2.25-beta.1
v2026.2.26
v2026.2.26-beta.1
v2026.2.3
v2026.2.6
v2026.2.6-1
v2026.2.6-2
v2026.2.6-3
v2026.2.9
v2026.3.1
v2026.3.11
v2026.3.11-beta.1
v2026.3.12
v2026.3.13
v2026.3.13-1
v2026.3.2
v2026.3.2-beta.1
v2026.3.22
v2026.3.22-beta.1
v2026.3.23
v2026.3.23-beta.1
v2026.3.7
v2026.3.7-beta.1
v2026.3.8
v2026.3.8-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35631.json"