Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35660

27
FAUCET Score

CVE-2026-35660 is an insufficient access control vulnerability affecting OpenClaw versions prior to 2026.3.23, specifically in the Gateway agent /reset endpoint. The flaw permits users with operator.write permissions to reset admin sessions and bypass operator.admin authorization requirements by invoking /reset or /new messages with an explicit sessionKey parameter, potentially allowing unauthorized session manipulation. The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. While no confidentiality impact exists, the flaw poses high integrity and availability risks through unauthorized session termination and administrative action bypass. The attack requires valid operator.write credentials but no user interaction. Exploitation status indicates this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and is not included on active public exploit lists. Community attention remains minimal, as reflected in the EPSS score of 0.00045, which is lower than 99.86% of all CVEs. Organizations should prioritize patching to version 2026.3.23 or later, particularly for systems where operator.write accounts may be less restricted than intended.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.23CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.23CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

7.2HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 7th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.3.23

Vendor Advisories (1)

npmGHSA-wq58-2pvg-5h4fhigh

OpenClaw: Gateway agent /reset exposes admin session reset to operator.write callers

Mar 26, 2026

References

github.com / openclaw/openclaw/commit/50f6a2f136fed85b58548a38f7a3dbb98d2cd1a0
Patch
github.com / openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-wq58-2pvg-5h4f
Vendor Advisory
vulncheck.com / advisories/openclaw-insufficient-access-control-in-gateway-agent-session-reset
Third Party Advisory