Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35664

20
FAUCET Score

EXECUTIVE SUMMARY CVE-2026-35664 is an authentication bypass vulnerability affecting OpenClaw versions prior to 2026.3.25. The flaw resides in the raw card send surface, enabling unauthenticated attackers to bypass DM pairing restrictions and reach callback handling mechanisms without proper authorization, potentially allowing the creation of legacy callback payloads. The vulnerability carries a CVSS 3.1 severity rating of 5.3 (Medium) with a network-based attack vector requiring no special privileges or user interaction. While the integrity impact is rated as low with no confidentiality or availability concerns, the zero authentication requirement lowers the barrier to exploitation. The FAUCET Risk Score of 41.0 out of 100 suggests moderate organizational risk. Exploitation appears limited at this time. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, and EPSS scoring indicates this CVE has lower exploitation probability compared to the broader CVE landscape. Community attention remains minimal with no indication of active exploitation campaigns or readily available public exploit code, though organizations running affected versions should prioritize patching to version 2026.3.25 or later.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.25CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.25CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 10th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.3.28

Vendor Advisories (1)

npmGHSA-77w2-crqv-cmv3medium

OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing

Mar 29, 2026

References

github.com / openclaw/openclaw/commit/81c45976db532324b5a0918a70decc19520dc354
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-77w2-crqv-cmv3
Vendor Advisory
vulncheck.com / advisories/openclaw-dm-pairing-bypass-via-legacy-card-callbacks
Third Party Advisory