CVE-2026-35638 | OpenClaw up to 2026.3.21 incorrect user management (GHSA-48vw-m3qc-wr99 / WID-SEC-2026-0856)
A vulnerability was found in OpenClaw up to 2026.3.21 and classified as critical. The affected element is an unknown function. Such manipulation leads to incorrect user management.
This vulnerability is referenced as CVE-2026-35638. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.