
CVE-2026-35624 OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers c… https://www.cve.org/CVERecord?id=CVE-2026-35624
Post summary
The text announces a policy‑confusion vulnerability (CVE‑2026‑35624) in OpenClaw 2026.3.22, noting that attackers could abuse room name collisions for unauthorized access. No exploits, patches, or active‑exploitation evidence are provided.

