CVE-2026-35638Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow path in the trusted-proxy mechanism to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-286

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-12: 104-0904-1004-12
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-101
Disclosure1
2026-04-121
Disclosure1
Full discourse5 posts
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 TODAY'S TOP 3 AGENT THREATS — 1. ghost session privilege takeover (CVE-2026-35638) unauthenticated sessions self-declare admin scopes without device verification and your control UI just believes them 2. scope laundering via pairing approval (CVE-2026-35639) low-privilege operators approve device pairings with broader scopes than they hold, granting themselves capabilities they were never authorized for 3. reconnect-to-admin bypass (CVE-2026-35663) non-admin operators request admin scopes during backend reconnect and bypass pairing requirements entirely is your agent on the list? → http://agentcop.live #AgentSecurity #CVE

    Post summary

    The post announces three new CVEs affecting agent capabilities, detailing how unauthorized privilege escalation and scope manipulation can occur, but does not provide PoC, exploit code, or patch information.

    0000037
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35638 Privilege Escalation in OpenClaw Control UI via Unauthenticated Scope Declaration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35638

    Post summary

    The text announces CVE‑2026‑35638 as a privilege‑escalation flaw in OpenClaw Control UI, detailing an unauthenticated scope declaration vector, but offers no PoC, patch, or exploitation evidence.

    0000054
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-35638: HIGH] URGENT: OpenClaw has a critical privilege escalation vulnerability in the Control UI, allowing unauthenticated users to retain elevated permissions by declaring arbitrary scopes and by...#cve,CVE-2026-35638,#cybersecurity https://cvefind.com/CVE-2026-35638

    Post summary

    The tweet announces a high‑severity privilege escalation flaw in OpenClaw’s Control UI that allows unauthenticated users to maintain elevated permissions by declaring arbitrary scopes, but it provides no PoC, exploit code, or patch information.

    0000089
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35638 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scop… https://www.cve.org/CVERecord?id=CVE-2026-35638 ----- Traducción: CVE-2026-35638 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-35638, a privilege‑escalation flaw in OpenClaw that allows unauthenticated sessions to retain privileged scopes, but provides no PoC, exploit, or patch details.

    0000042
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35638 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scop… https://www.cve.org/CVERecord?id=CVE-2026-35638

    Post summary

    A privilege escalation vulnerability has been disclosed for OpenClaw versions prior to 2026.3.22, affecting the Control UI.

    00000204
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more