CVE-2026-35638

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/04/2026
Last modified:
13/04/2026

Description

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow path in the trusted-proxy mechanism to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.