SB2026050450 - Improper access control in OpenClaw
Published: May 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2026-35636)
The vulnerability allows a remote user to access restricted parent or sibling sessions.
The vulnerability exists due to improper access control in the session_status sessionId resolution logic when resolving a supplied sessionId to a canonical session key. A remote user can supply a crafted sessionId to access restricted parent or sibling sessions.
The issue affects sandboxed session-tree visibility checks.
Remediation
Install update from vendor's website.