Authorization Header Forwarding Vulnerability in OpenClaw by OpenClaw
CVE-2026-62208

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62208?

The OpenClaw application prior to version 2026.6.5 presents a security vulnerability wherein Authorization headers may be improperly forwarded during MCP SSE redirects. This flaw allows lower-trust callers or paths that have access to the vulnerable feature to perform actions that exceed the intended authorization levels. The potential impact is largely contingent on the specific configurations set by the operator and whether untrusted inputs can access the affected pathways, raising substantial concerns for data integrity and access control.

Affected Version(s)

OpenClaw 0 < 2026.6.5

OpenClaw 2026.6.5

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liwei Ding (@dingliweixlm-byte)
.