CVE-2026-35638 is a privilege escalation vulnerability affecting OpenClaw versions prior to 2026.3.22, wherein the Control UI fails to verify device identity for unauthenticated sessions, allowing attackers to declare and retain arbitrary elevated permissions. The vulnerability exploits a device-less allowance path in the trusted-proxy mechanism, enabling unauthorized users to bypass authentication and authorization controls. The vulnerability carries a CVSS score of 8.8 (High), with a network-based attack vector requiring low complexity and low privileges to execute. It poses significant risk across all three impact categories: compromised confidentiality, integrity, and availability of affected systems. The attack requires no user interaction, making it particularly concerning for exposed environments. There is currently no evidence of active exploitation in the wild, and the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. The EPSS probability score of 0.00048 indicates relatively low expected exploitation likelihood compared to the broader CVE population. However, organizations running vulnerable OpenClaw versions should prioritize patching to version 2026.3.22 or later to mitigate the risk of potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.22CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.22CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.