CVE-2026-35647

MEDIUM

OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send verification notices to users outside allowed direct message policies by exploiting insufficient access validation before message transmission.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-9wqx-g2cw-vc7r)
https://github.com/openclaw/openclaw/security/advisories/GHSA-9wqx-g2cw-vc7r
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices
https://www.vulncheck.com/advisories/openclaw-direct-message-policy-bypass-via-verification-notices

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-288
Status published
Products (4)
npm/openclaw 0npm
OpenClaw/OpenClaw < 2026.3.25
openclaw/openclaw < 2026.3.25
OpenClaw/OpenClaw 2026.3.25
Published Apr 10, 2026
Tracked Since Apr 10, 2026