
🚨 LIVE HIJACK ALERT — CVE-2026-35645. CVSS 8.1. openclaw agents hand out admin scope during session cleanup. attackers trigger deletion without client context. instant privilege escalation. investigating. 🧵
Post summary
A newly identified privilege‑escalation weakness (CVE‑2026‑35645) in Openclaw agents allows attackers to trigger session cleanup deletions without client context, granting admin scope; the flaw is under investigation with no evidence of widespread exploitation or available patches.



