{"id":"CVE-2026-35621","aliases":["GHSA-94pw-c6m8-p9p9"],"url":"https://o3.security/vulnerability/CVE-2026-35621","summary":"OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist Persistence","details":"OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, allowing operator.write-scoped clients to mutate channel authorization policy. Attackers can exploit chat.send to build an internal command-authorized context and persist channel allowFrom and groupAllowFrom policy changes reserved for operator.admin scope.","published":"2026-04-10T16:03:09.856Z","modified":"2026-08-07T11:31:24.558808858Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.3.24"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35621.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-94pw-c6m8-p9p9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35621"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-chat-send-to-allowlist-persistence"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:24.558808858Z"}}