Junglewise Threat Intelligence

CVE-2026-62187: OpenClaw Feishu tools authorization bypass in per-account disablement

CVE-2026-62187 · Severity: high · CVSS 8.1 · Published 2026-07-13

Technologies: @openclaw/feishu (npm), Openclaw, Openclaw Feishu. Vendors: npm, Openclaw.

Executive brief

OpenClaw is an AI automation platform used to execute tasks across operating systems and platforms. The Feishu integration (a collaboration tool connector) failed to properly enforce per-account access restrictions, allowing users or processes with lower privileges to perform actions that should have been blocked by administrator settings. An attacker could bypass authorization checks to access Feishu features (documents, apps, drive, wiki, permissions) on accounts where those features were disabled, potentially leading to unauthorized data access or modification.

Technical details

The vulnerability is a missing authorization check (CWE-863) in OpenClaw's Feishu extension for account-routed tools. When a Feishu account has a specific tool family disabled (doc, app scopes, drive, wiki, or permissions tools), the Feishu SDK client is created before validating whether the resolved account permits that tool family. A lower-trust caller or configured input path can supply an account reference that should be rejected, and the tool proceeds to execute using that account despite the disablement setting. The fix, merged in PR #93363, enforces the account's own tool-family gate before Feishu client creation, rejecting disabled accounts at the validation stage. Attack vector is network, requires low privilege (authenticated user with tool access), no user interaction, and results in high confidentiality and integrity impact (reading/modifying data across Feishu resources). Patches are available in version 2026.6.9 and later.

Affected products

  • OpenClaw @openclaw/feishu < 2026.6.9

Timeline

  • 2026-09-03: disclosed: Advisory published
  • 2026-06-17: patched: Fix merged in PR #93363
  • 2026-06-30: patched: Stable patched version 2026.6.9 released

References

Related threats