
CVE-2026-35648 OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attacker… https://www.cve.org/CVERecord?id=CVE-2026-35648
Post summary
The entry announces a policy bypass vulnerability in OpenClaw prior to 2026.3.22, where queued node actions aren’t revalidated against the current command policy, with no evidence of exploitation or mitigation.


