CVE-2026-35625 | OpenClaw up to 2026.3.24 operator.admin incorrect privileged apis (GHSA-fqw4-mph7-2vr8)
A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.24. Affected is the function operator.admin. This manipulation causes incorrect use of privileged apis.
This vulnerability appears as CVE-2026-35625. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.