
CVE-2026-35662 OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond their aut… https://www.cve.org/CVERecord?id=CVE-2026-35662
Post summary
The snippet offers a concise vulnerability description for CVE-2026-35662, noting improper controlScope enforcement in OpenClaw versions prior to 2026.3.22, but provides no PoC, exploit, or mitigation details.
