CVE-2026-35663Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attackers can bypass pairing requirements to reconnect as operator.admin, gaining unauthorized administrative privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-648

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-10); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Mentions · 2026-04-12: 2Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 204-1004-1104-12
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure1Patch1
2026-04-111
Disclosure1
2026-04-122
Disclosure2
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35663 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attacker… https://www.cve.org/CVERecord?id=CVE-2026-35663

    Post summary

    The post announces CVE-2026-35663, a privilege‑escalation vulnerability in OpenClaw before version 2026.3.25, allowing non-admin operators to increase their scope during a backend reconnect. No additional exploit, patch, or active‑exploitation details are provided.

    00010146
    57.0K followersView on X
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 TODAY'S TOP 3 AGENT THREATS — 1. ghost session privilege takeover (CVE-2026-35638) unauthenticated sessions self-declare admin scopes without device verification and your control UI just believes them 2. scope laundering via pairing approval (CVE-2026-35639) low-privilege operators approve device pairings with broader scopes than they hold, granting themselves capabilities they were never authorized for 3. reconnect-to-admin bypass (CVE-2026-35663) non-admin operators request admin scopes during backend reconnect and bypass pairing requirements entirely is your agent on the list? → http://agentcop.live #AgentSecurity #CVE

    Post summary

    The post announces three agent privilege escalation vulnerabilities (CVE‑2026‑35638, ‑35639, ‑35663), explaining how attackers can gain admin rights without proper verification, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000037
    6 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `OpenClaw` gateway backend is affected by CVE-2026-35663, allowing non-admin operators to self-claim admin privileges. This can lead to unauthorized administrative control. Review your `OpenClaw` deployments. #InfoSec #CyberSecurity #PrivilegeEscalation https://www.pulsepatch.io/posts/cve-2026-35663-openclaw-privilege-escalation

    Post summary

    CVE-2026-35663 permits non‑admin operators to elevate themselves to admin privileges in the OpenClaw gateway backend, potentially enabling unauthorized control; no patch or exploit details are provided.

    0000051
    13 followersView on X
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 TODAY'S TOP 3 AGENT THREATS — 1. reconnect privilege escalation (CVE-2026-35663) non-admin operators self-grant admin privileges during backend reconnect by bypassing pairing requirements 2. scope boundary bypass via gateway routes (CVE-2026-35669) plugin HTTP routes incorrectly mint operator.admin scope regardless of caller permissions, handing attackers elevated privileges 3. session reset access control failure (CVE-2026-35660) attackers with operator.write can reset admin sessions via /reset endpoint, hijacking administrative control is your agent on the list? → http://agentcop.live #AgentSecurity #CVE

    Post summary

    The post announces three newly disclosed Agent CVEs, detailing privilege escalation and access-control flaws, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000046
    6 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35663: HIGH] URGENT: OpenClaw before 2026.3.25 has a critical privilege escalation vulnerability. Attackers can gain admin access by bypassing pairing requirements. Update now!#cve,CVE-2026-35663,#cybersecurity https://cvefind.com/CVE-2026-35663

    Post summary

    OpenClaw versions before 2026.3.25 suffer a critical privilege escalation flaw that bypasses pairing requirements; users are urged to apply the patch immediately.

    0000057
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more