CVE-2026-35634: Openclaw

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. Attackers can send unauthenticated loopback HTTP and WebSocket requests to Canvas routes to bypass authentication and gain unauthorized access.

Affected products

  • Openclaw Openclaw: before 2026.3.23 (fixed in 2026.3.23)

Published 2026-04-09. Last modified 2026-06-17.