EXECUTIVE SUMMARY CVE-2026-35664 is an authentication bypass vulnerability affecting OpenClaw versions prior to 2026.3.25. The flaw resides in the raw card send surface, enabling unauthenticated attackers to bypass DM pairing restrictions and reach callback handling mechanisms without proper authorization, potentially allowing the creation of legacy callback payloads. The vulnerability carries a CVSS 3.1 severity rating of 5.3 (Medium) with a network-based attack vector requiring no special privileges or user interaction. While the integrity impact is rated as low with no confidentiality or availability concerns, the zero authentication requirement lowers the barrier to exploitation. The FAUCET Risk Score of 41.0 out of 100 suggests moderate organizational risk. Exploitation appears limited at this time. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, and EPSS scoring indicates this CVE has lower exploitation probability compared to the broader CVE landscape. Community attention remains minimal with no indication of active exploitation campaigns or readily available public exploit code, though organizations running affected versions should prioritize patching to version 2026.3.25 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.25CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.25CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.