CVE-2026-35617: OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unauthorized access to protected resources.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35617?
CVE-2026-35617 is classified as a medium severity vulnerability due to its potential for exploitation in authorization bypass scenarios.
How do I fix CVE-2026-35617?
To mitigate CVE-2026-35617, upgrade OpenClaw to version 2026.3.25 or later.
What type of vulnerability is CVE-2026-35617?
CVE-2026-35617 is an authorization bypass vulnerability that affects group policy enforcement.
What are the affected versions for CVE-2026-35617?
CVE-2026-35617 affects OpenClaw versions prior to 2026.3.25.
Can CVE-2026-35617 be exploited remotely?
Yes, CVE-2026-35617 can be exploited remotely if an attacker can manipulate group policies through mutable space display names.