VYPR
High severity8.0NVD Advisory· Published May 29, 2026· Updated Jul 21, 2026

CVE-2026-35630

CVE-2026-35630

Description

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
openclawnpm
< 2026.5.182026.5.18

Affected products

4
  • OpenClaw/Openclawllm-fuzzy3 versions
    <2026.5.18+ 2 more
    • (no CPE)range: <2026.5.18
    • (no CPE)range: <2026.5.18
    • cpe:2.3:a:openclaw:openclaw:*:-:*:*:*:node.js:*:*range: <2026.5.18
  • OpenClaw/QQBotllm-create
    Range: <2026.5.18

Patches

Vulnerability mechanics

References

4

News mentions

1