Improper access control in OpenClaw - CVE-2026-35622
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass webhook authentication.
The vulnerability exists due to improper access control in Google Chat app-url webhook verification when validating add-on principals. A remote attacker can send a webhook request using an add-on principal outside the intended deployment binding to bypass webhook authentication.