Authorization Header Forwarding Vulnerability in OpenClaw by OpenClaw
CVE-2026-62208
6MEDIUM
What is CVE-2026-62208?
The OpenClaw application prior to version 2026.6.5 presents a security vulnerability wherein Authorization headers may be improperly forwarded during MCP SSE redirects. This flaw allows lower-trust callers or paths that have access to the vulnerable feature to perform actions that exceed the intended authorization levels. The potential impact is largely contingent on the specific configurations set by the operator and whether untrusted inputs can access the affected pathways, raising substantial concerns for data integrity and access control.
Affected Version(s)
OpenClaw 0 < 2026.6.5
OpenClaw 2026.6.5
