CVE-2026-35645 | OpenClaw up to 2026.3.24 operator.admin incorrect privileged apis (GHSA-h4jx-hjr3-fhgc)
A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.24. This issue affects the function operator.admin. The manipulation leads to incorrect use of privileged apis.
This vulnerability is traded as CVE-2026-35645. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.