
CVE-2026-35620 OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command… https://www.cve.org/CVERecord?id=CVE-2026-35620
Post summary
The post discloses a missing‑authorization flaw in OpenClaw’s /send and /allowlist chat commands that could be abused by non‑owners.

