CVE-2026-35656 | OpenClaw up to 2026.3.21 Header X-Forwarded-For authentication spoofing (GHSA-844j-xrrq-wgh4 / WID-SEC-2026-0856)
A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.21. Impacted is an unknown function of the component Header Handler. The manipulation of the argument X-Forwarded-For results in authentication bypass by spoofing.
This vulnerability is identified as CVE-2026-35656. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.