CVE-2026-35663
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/04/2026
Last modified:
10/04/2026
Description
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attackers can bypass pairing requirements to reconnect as operator.admin, gaining unauthorized administrative privileges.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



