
CVE-2026-35653 OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.write … https://www.cve.org/CVERecord?id=CVE-2026-35653
Post summary
The text announces a CVE‐dated incorrect authorization flaw in OpenClaw’s /reset‑profile endpoint, enabling authenticated operator.write users to exploit the issue.
