Junglewise Threat Intelligence

CVE-2026-35647: OpenClaw access control bypass in direct message verification notices

CVE-2026-35647 · Severity: medium · CVSS 5.3 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a library used for Matrix protocol communications, contains a flaw where verification notices can bypass direct message (DM) security policies. This allows the system to respond to unauthorized or unpaired users, potentially leading to unintended communication or data leakage between parties who should not be connected. Organizations using this library for secure messaging should update to ensure their communication policies are strictly enforced.

Technical details

OpenClaw versions up to 2026.3.24 contain an authorization bypass (CWE-288/CWE-863) in the handling of Matrix verification notices. The vulnerability occurs because verification notices were not gated by DM access checks, allowing the library to reply to peers that were unpaired or otherwise restricted by the configured DM policy. An attacker with low privileges can exploit this over the network to interact with users outside of authorized channels. The issue was addressed in version 2026.3.25 by implementing mandatory DM access validation before sending verification notices.

Affected products

  • openclaw openclaw <= 2026.3.24

Timeline

  • 2026-03-26: patched: Fix committed to main branch
  • 2026-03-27: advisory: GitHub Advisory published

References

Related threats