Policy Bypass Vulnerability in OpenClaw Media Upload Feature
CVE-2026-62216
2.3LOW
What is CVE-2026-62216?
The OpenClaw application versions 2026.4.20 and earlier are susceptible to a policy bypass issue in the media upload feature. This vulnerability allows a lower-trust caller or an improperly configured input path to exploit the media upload functionality, potentially enabling unauthorized access to restricted network destinations that should be blocked according to OpenClaw's security policies. The severity of the impact is contingent upon the specific configuration of the system and the pathway of lower-trust inputs. Operators should review their configurations to mitigate potential security risks.
Affected Version(s)
OpenClaw 2026.4.20 < 2026.5.28
OpenClaw 2026.5.28
