Policy Bypass Vulnerability in OpenClaw Media Upload Feature
CVE-2026-62216

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62216?

The OpenClaw application versions 2026.4.20 and earlier are susceptible to a policy bypass issue in the media upload feature. This vulnerability allows a lower-trust caller or an improperly configured input path to exploit the media upload functionality, potentially enabling unauthorized access to restricted network destinations that should be blocked according to OpenClaw's security policies. The severity of the impact is contingent upon the specific configuration of the system and the pathway of lower-trust inputs. Operators should review their configurations to mitigate potential security risks.

Affected Version(s)

OpenClaw 2026.4.20 < 2026.5.28

OpenClaw 2026.5.28

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.