
CVE-2026-35657 OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips http://operator.read scope validation. At… https://www.cve.org/CVERecord?id=CVE-2026-35657
Post summary
The text announces that OpenClaw versions before 2026.3.25 have an authorization bypass flaw allowing access to /sessions/:sessionKey/history without the required operator.read scope.
