CVE-2026-35630
OpenClaw OpenClaw, openclaw
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.
- CVSS
- 7.5
- EPSS
- 0.21% 10.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.30