
CVE-2026-35666 OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in http://system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers can bypass executa… https://www.cve.org/CVERecord?id=CVE-2026-35666
Post summary
The provided snippet describes CVE-2026-35666 as an allowlist bypass in OpenClaw’s system.run approvals but offers no PoC, exploit code, active exploitation evidence, or patch information.

