
CVE-2026-35621 OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, … https://www.cve.org/CVERecord?id=CVE-2026-35621
Post summary
The statement reports a privilege escalation flaw in OpenClaw before version 2026.3.24, noting that the /allowlist command does not re-validate gateway client scopes for internal callers.

