Authorization Bypass in OpenClaw Skill Command Dispatch
CVE-2026-62225

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62225?

OpenClaw versions preceding 2026.5.18 are vulnerable to an authorization bypass issue within the skill command dispatch feature. This flaw permits lower-privileged users to execute or store actions that exceed their intended permissions. If the affected feature is both enabled and accessible, attackers can leverage specific input paths to bypass policy restrictions, leading to unauthorized actions that compromise the application's security integrity.

Affected Version(s)

OpenClaw 0 < 2026.5.18

OpenClaw 2026.5.18

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsxsoft
KeenSecurityLab
.