CVE-2026-35637

openclaw: Incorrect Behavior Order (CVE-2026-35637)

Description

OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or manipulate content before proper authorization validation occurs.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

npmopenclaw

Metrics

7.3
Source: nvd-v3
34.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-09 21:27 UTC
CWE-696

Weakness classes (CWE)

  • CWE-696Class

    Incorrect Behavior Order

    The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

    cwe.mitre.org →

References & sources