Authentication Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-62215

5.1MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62215?

OpenClaw before version 2026.6.5 is susceptible to an authentication bypass vulnerability. This flaw allows attackers with lower trust levels to forge trusted A2UI actions by crafting malicious requests through input paths. As a result, attackers can circumvent intended authorization checks, leading to potentially unauthorized access to sensitive functions. Users are urged to update to the latest version to mitigate this risk.

Affected Version(s)

OpenClaw 0 < 2026.6.5

OpenClaw 2026.6.5

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jidle (@jidle123)
.