OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty allowlist handling. The vulnerability treats explicit empty allowlists as unset during reconciliation, silently undoing intended access control denials and restoring previously revoked permissions.
References
Configurations
History
13 Apr 2026, 20:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
|
| References | () https://github.com/openclaw/openclaw/commit/3cbf932413e41d1836cb91aed1541a28a3122f93 - Patch | |
| References | () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-pw7h-9g6p-c378 - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-settings-reconciliation-bypass-via-empty-allowlist - Third Party Advisory |
10 Apr 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 17:17
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35649
Mitre link : CVE-2026-35649
CVE.ORG link : CVE-2026-35649
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-183
Permissive List of Allowed Inputs
