
CVE-2026-35655 OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicting tool identity hints from rawInput and metad… https://www.cve.org/CVERecord?id=CVE-2026-35655
Post summary
The text reports an identity spoofing vulnerability (CVE‑2026‑35655) in OpenClaw’s ACP permission system, providing technical details but no PoC, patch information, or evidence of active exploitation.
