PT-2026-31975 · Openclaw · Openclaw

·

CVE-2026-35664

·

Published

2026-03-29

·

Updated

2026-04-10

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.25
Description OpenClaw contains an authentication bypass issue in the raw card send surface. This allows unpaired recipients to create legacy callback payloads, bypassing DM pairing restrictions and reaching callback handling without authorization. The issue was resolved by rejecting legacy raw-card command payloads, ensuring callbacks remain on the normal paired path.
Recommendations Update to version 2026.3.25 or later.

Exploit

Fix

Incorrect Authorization

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35664
GHSA-77W2-CRQV-CMV3

Affected Products

Openclaw