
CVE-2026-35664 OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy callback payloads. A… https://www.cve.org/CVERecord?id=CVE-2026-35664
Post summary
The statement announces CVE-2026-35664 as an authentication bypass vulnerability in OpenClaw, enabling unpaired recipients to mint legacy callback payloads, without providing any exploitation code, active exploitation evidence, or patch information.
