
CVE-2026-35647 OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send … https://www.cve.org/CVERecord?id=CVE-2026-35647
Post summary
The post details an access control vulnerability in OpenClaw that lets verification notices bypass DM policy checks; it does not provide PoC code, exploit tools, or evidence of active exploitation, nor mention any patch.

