CVE-2026-35674: OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope requirements, enabling unauthorized plugin, config, MCP, allowlist, and ACP mutations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.18 - Compensating control
If you cannot immediately upgrade, restrict/limit access to the Gateway chat.send route so scoped clients cannot use inherited external routes to execute privileged commands (scope bypass via inherited chat.send route).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35674?
The severity of CVE-2026-35674 is rated high with a score of 8.7.
How do I fix CVE-2026-35674?
To fix CVE-2026-35674, upgrade OpenClaw to version 2026.5.18 or later.
What systems are affected by CVE-2026-35674?
CVE-2026-35674 affects all versions of OpenClaw prior to 2026.5.18.
What type of vulnerability is CVE-2026-35674?
CVE-2026-35674 is a scope bypass vulnerability in the Gateway chat.send route.
What can attackers do with CVE-2026-35674?
Attackers can use CVE-2026-35674 to execute privileged commands by bypassing scoped access controls.