Junglewise Threat Intelligence

CVE-2026-35637: OpenClaw incorrect authorization in Tlon cite expansion

CVE-2026-35637 · Severity: medium · CVSS 4 · Published 2026-03-26

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a software package used for managing communications. A vulnerability was found where the system would process and expand content links (cites) before verifying if the user was actually authorized to access the specific channel or direct message. This could allow unauthorized users to trigger content handling processes and potentially view or interact with data they should not have access to.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's Tlon extension. The root cause is that cite expansion—the process of fetching and rendering referenced content—is triggered before the final authorization check for channels and direct messages is completed. A network-based attacker with low privileges can exploit this to force the system to perform cite work and content handling before an access decision is made. This could lead to unauthorized disclosure or modification of data. The issue is fixed in version 2026.3.22 by deferring cite expansion until after authorization is confirmed.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-24: patched: Fix shipped in v2026.3.22
  • 2026-03-26: advisory: GitHub Advisory published

References

Related threats