
CVE-2026-35631 OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin p… https://www.cve.org/CVERecord?id=CVE-2026-35631
Post summary
The post highlights a security flaw in OpenClaw before version 2026.3.22 involving improper enforcement of operator.admin scope, enabling unauthorized modifications via internal chat commands.


