OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validation. Attackers can access session history without proper operator read permissions by sending HTTP requests to the vulnerable endpoint.
References
Configurations
History
13 Apr 2026, 21:08
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/1c45123231516fa50f8cf8522ba5ff2fb2ca7aea - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-5jvj-hxmh-6h6j - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-http-session-history-route - Third Party Advisory | |
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
10 Apr 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 17:17
Updated : 2026-04-13 21:08
NVD link : CVE-2026-35657
Mitre link : CVE-2026-35657
CVE.ORG link : CVE-2026-35657
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
