Improper access control in OpenClaw - CVE-2026-35636
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to access restricted parent or sibling sessions.
The vulnerability exists due to improper access control in the session_status sessionId resolution logic when resolving a supplied sessionId to a canonical session key. A remote user can supply a crafted sessionId to access restricted parent or sibling sessions.
The issue affects sandboxed session-tree visibility checks.