Skip to main content
EPSS 0.5%top 57%

Openclaw cli: OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy (CVE-2026-35620)

0
Medium
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

OpenClaw CLI versions from 2026.1.29 up to but not including 2026.3.24 contain an authorization bypass vulnerability (CVE-2026-35620) that allows a non-owner command-authorized sender to change the owner-only `/send` session delivery policy. This flaw permits persistent mutation of the current session's delivery policy, enabling lower-trust participants to disable or re-enable reply delivery or remove session overrides, despite `/send` being documented as owner-only. The vulnerability has a medium severity rating with a CVSS score of 5.4. A fix is available in OpenClaw version 2026.3.24.

CVSS v3.1

Score 5.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
>=2026.1.29 <2026.3.24

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 13:20:14 UTC

Technical Analysis

CVE-2026-35620 is an improper authorization vulnerability in OpenClaw CLI affecting versions >=2026.1.29 and <2026.3.24. The issue arises because the handler for the `/send` command checks only if the sender is command-authorized, not whether the sender is the owner, allowing non-owner authorized users to persistently modify the session's sendPolicy. This bypasses the documented owner-only restriction on the `/send on|off|inherit` commands, enabling lower-trust users to alter reply delivery behavior for the current session. The vulnerability was verified in the source code at specific commits and release tags, and the vendor has fixed the issue in version 2026.3.24.

Potential Impact

The vulnerability allows a non-owner but command-authorized sender to persistently change the session delivery policy by invoking `/send on|off|inherit`. This can disable reply delivery, re-enable it after owner-disabled, or remove session overrides, affecting the communication flow in the current session. There is no direct impact on confidentiality, but integrity and availability of session replies are affected. The vulnerability does not lead to code execution, sandbox escape, or cross-host compromise.

Mitigation Recommendations

A patch is available and has been released in OpenClaw version 2026.3.24. Users should upgrade to this version or later to remediate the vulnerability. No additional mitigation actions are required as the fix addresses the authorization bypass directly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-CVE-2026-35620
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6ac245d812601ec6a31680a1

Added to database: 10/04/2026, 12:26:00 UTC

Last enriched: 10/04/2026, 13:20:14 UTC

Last updated: 10/04/2026, 16:08:37 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses