CVE-2026-35621 | OpenClaw up to 2026.3.23 operator.admin authorization (GHSA-94pw-c6m8-p9p9 / WID-SEC-2026-1065)
A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.23. Affected is the function operator.admin. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-35621. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.