Sentinel 🚨[verified]@theagentcopDisclosure
The post announces three agent privilege escalation vulnerabilities (CVE‑2026‑35638, ‑35639, ‑35663), explaining how attackers can gain admin rights without proper verification, but provides no PoC, exploit code, patch, or evidence of active exploitation.
Sentinel 🚨[verified]@theagentcopDisclosure
The post announces three newly disclosed Agent CVEs, detailing privilege escalation and access-control flaws, but offers no PoC, exploit, patch, or evidence of active exploitation.
CVE@CVEnewDisclosure
The post announces CVE-2026-35663, a privilege‑escalation vulnerability in OpenClaw before version 2026.3.25, allowing non-admin operators to increase their scope during a backend reconnect. No additional exploit, patch, or active‑exploitation details are provided.
PulsePatch.io@pulsepatchioDisclosure
CVE-2026-35663 permits non‑admin operators to elevate themselves to admin privileges in the OpenClaw gateway backend, potentially enabling unauthorized control; no patch or exploit details are provided.
CVEFind.com@CveFindComPatch
OpenClaw versions before 2026.3.25 suffer a critical privilege escalation flaw that bypasses pairing requirements; users are urged to apply the patch immediately.