CVE-2026-35663 | OpenClaw up to 2026.3.24 operator.admin incorrect privileged apis (GHSA-9hjh-fr4f-gxc4)
A vulnerability was found in OpenClaw up to 2026.3.24. It has been classified as critical. The affected element is the function operator.admin. The manipulation leads to incorrect use of privileged apis.
This vulnerability is traded as CVE-2026-35663. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.