Authorization Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-62223
7.7HIGH
What is CVE-2026-62223?
OpenClaw versions prior to 2026.5.18 are vulnerable to an authorization bypass in the device-pair approval feature. This vulnerability allows lower-trust callers to perform actions that exceed their designated permissions. Attackers can manipulate misconfigured input paths to execute unauthorized actions, making this a critical concern for users who have enabled the affected feature. Immediate review and updates to the system configurations are recommended to mitigate risks.
Affected Version(s)
OpenClaw 0 < 2026.5.18
OpenClaw 2026.5.18
