CVE-2026-35635: OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account DM access control policies and replace route ownership across accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35635?
The severity of CVE-2026-35635 is medium, with a CVSS score of 6.3.
How do I fix CVE-2026-35635?
To fix CVE-2026-35635, update OpenClaw to version 2026.3.22 or later.
What type of vulnerability is CVE-2026-35635?
CVE-2026-35635 is a webhook path route replacement vulnerability in the Synology Chat extension.
What can attackers exploit in CVE-2026-35635?
Attackers can exploit CVE-2026-35635 to bypass per-account DM access controls via inherited or duplicate webhook paths.
Which software is affected by CVE-2026-35635?
CVE-2026-35635 affects OpenClaw, specifically versions prior to 2026.3.22.