Authorization Bypass in OpenClaw by OpenClaw Inc.
CVE-2026-62226

5.1MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62226?

The authorization bypass vulnerability in OpenClaw versions prior to 2026.5.19 allows attackers with lower-trust access to exploit the browser act route due to insufficient URL validation. This flaw can enable unauthorized actions that typically require elevated permissions or stricter policy enforcement, posing significant risks to the security of affected systems.

Affected Version(s)

OpenClaw 2026.3.28 < 2026.5.19

OpenClaw 2026.5.19

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsxsoft
KeenSecurityLab
.