CVE-2026-35660 is an insufficient access control vulnerability affecting OpenClaw versions prior to 2026.3.23, specifically in the Gateway agent /reset endpoint. The flaw permits users with operator.write permissions to reset admin sessions and bypass operator.admin authorization requirements by invoking /reset or /new messages with an explicit sessionKey parameter, potentially allowing unauthorized session manipulation. The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. While no confidentiality impact exists, the flaw poses high integrity and availability risks through unauthorized session termination and administrative action bypass. The attack requires valid operator.write credentials but no user interaction. Exploitation status indicates this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and is not included on active public exploit lists. Community attention remains minimal, as reflected in the EPSS score of 0.00045, which is lower than 99.86% of all CVEs. Organizations should prioritize patching to version 2026.3.23 or later, particularly for systems where operator.write accounts may be less restricted than intended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.23CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.23CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.