
CVE-2026-32035 OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true… https://www.cve.org/CVERecord?id=CVE-2026-32035
Post summary
CVE-2026-32035 identifies a flaw in OpenClaw where the senderIsOwner flag defaults to true during processing of Discord voice transcripts; the vulnerability is fixed in 2026.3.2, but no PoC or exploitation details are provided.
