HarborGuard / CVE
Back to search
HIGHCVE-2026-35657Published Modified CNA VulnCheck

CVE-2026-35657: OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validation. Attackers can access session history without proper operator read permissions by sending HTTP requests to the vulnerable endpoint.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
2026.3.25
Affected Products
1

Fix available

2026.3.25
Patch commits
Affected packages
  • OpenClaw / OpenClaw
    < 2026.3.25 (from 0)
    Fixed in 2026.3.25
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N