CVE-2026-35618
- EPSS 0.28%
- Veröffentlicht 09.04.2026 22:16:30
- Zuletzt bearbeitet 17.04.2026 12:20:03
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL includi...
CVE-2026-35622
- EPSS 0.29%
- Veröffentlicht 09.04.2026 22:16:30
- Zuletzt bearbeitet 17.04.2026 12:19:18
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authentication by provi...
CVE-2026-35623
- EPSS 0.36%
- Veröffentlicht 09.04.2026 22:16:30
- Zuletzt bearbeitet 16.04.2026 14:17:26
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to th...
CVE-2026-35624
- EPSS 0.24%
- Veröffentlicht 09.04.2026 22:16:30
- Zuletzt bearbeitet 17.04.2026 12:18:26
OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized ...
CVE-2026-35625
- EPSS 0.19%
- Veröffentlicht 09.04.2026 22:16:30
- Zuletzt bearbeitet 16.04.2026 13:43:35
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers can exploit this...
CVE-2026-34512
- EPSS 0.35%
- Veröffentlicht 09.04.2026 22:16:29
- Zuletzt bearbeitet 15.04.2026 17:23:36
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. At...
CVE-2026-35617
- EPSS 0.24%
- Veröffentlicht 09.04.2026 22:16:29
- Zuletzt bearbeitet 16.04.2026 14:19:04
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unau...
CVE-2026-40037
- EPSS 0.24%
- Veröffentlicht 08.04.2026 21:35:29
- Zuletzt bearbeitet 24.07.2026 21:10:00
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exf...
CVE-2026-34511
- EPSS 0.24%
- Veröffentlicht 03.04.2026 20:45:41
- Zuletzt bearbeitet 24.07.2026 22:10:00
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating ...
CVE-2026-34426
- EPSS 0.26%
- Veröffentlicht 02.04.2026 18:25:14
- Zuletzt bearbeitet 24.07.2026 21:10:00
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment variables int...