CVE-2026-35647 | OpenClaw up to 2026.3.24 Direct Message authentication bypass (GHSA-9wqx-g2cw-vc7r)
A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.24. Affected by this vulnerability is an unknown functionality of the component Direct Message Handler. Executing a manipulation can lead to authentication bypass using alternate channel.
The identification of this vulnerability is CVE-2026-35647. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.