CVE-2026-35657 is an authorization bypass vulnerability affecting OpenClaw versions prior to 2026.3.25, where the HTTP /sessions/:sessionKey/history route fails to validate the operator.read scope, allowing attackers to access session history without proper permissions. The vulnerability has a CVSS score of 6.5 (Medium) with a network-based attack vector requiring low complexity and low privileges, resulting in high confidentiality impact but no integrity or availability compromise. Exploitation requires authenticated access (PR:L) and poses moderate risk through unauthorized data disclosure. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows minimal exploitation activity, with an EPSS score of 0.00026 indicating it ranks higher than only 0.0724 percent of all CVEs in terms of real-world exploitation likelihood. Community attention appears limited, and no public exploit code is readily available, though organizations running affected versions should still prioritize patching to version 2026.3.25 or later to eliminate the authorization control gap.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.25CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.25CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.