Authorization Flaw in OpenClaw Product by OpenClaw
CVE-2026-62217
7.7HIGH
What is CVE-2026-62217?
An authorization issue exists in OpenClaw prior to version 2026.5.27 related to the QQBot exec approvals feature. When this feature is activated, it can be exploited by low-trust callers or through misconfigured input paths, enabling unauthorized users to execute actions or persist changes outside their intended permissions. This flaw can lead to non-allowlisted senders performing operations that should be restricted, compromising application integrity.
Affected Version(s)
OpenClaw 2026.5.14-beta.1 < 2026.5.27
OpenClaw 2026.5.27
