Authorization Bypass in OpenClaw Product by OpenClaw
CVE-2026-62221
2.3LOW
What is CVE-2026-62221?
OpenClaw versions prior to 2026.5.26 suffer from an authorization bypass vulnerability within the ClickClack allowFrom feature. When this feature is enabled, it allows lower-trust callers or misconfigured input paths to perform actions that exceed their intended permissions. This flaw could permit the execution of non-allowlisted commands, potentially compromising system integrity. Users are advised to upgrade to version 2026.5.26 or later to mitigate these risks.
Affected Version(s)
OpenClaw 2026.5.12 < 2026.5.26
OpenClaw 2026.5.26
