CVE-2026-35624: OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk
Published Apr 9, 2026
·Updated
OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms.
Affected Software
2 affected components
OpenClaw OpenClaw<2026.3.22
OpenClaw Openclaw Node.js<2026.3.22
Remediation
Event History
Apr 9, 2026
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35624?
The severity of CVE-2026-35624 is classified as low.
2
How do I fix CVE-2026-35624?
To fix CVE-2026-35624, you need to update OpenClaw to version 2026.3.22 or later.
3
What type of vulnerability is CVE-2026-35624?
CVE-2026-35624 is a policy confusion vulnerability that affects room authorization in Nextcloud Talk.
4
What can attackers do with CVE-2026-35624?
Attackers can exploit CVE-2026-35624 to gain unauthorized access to protected Nextcloud Talk rooms by leveraging colliding room names.
5
Which software versions are affected by CVE-2026-35624?
CVE-2026-35624 affects OpenClaw versions prior to 2026.3.22.