CVE-2026-35661 | OpenClaw up to 2026.3.24 Direct Message authentication bypass (GHSA-j4c9-w69r-cw33)
A vulnerability, which was classified as critical, has been found in OpenClaw up to 2026.3.24. This affects an unknown part of the component Direct Message Handler. This manipulation causes authentication bypass using alternate channel.
This vulnerability is registered as CVE-2026-35661. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.