Junglewise Threat Intelligence

CVE-2026-62191: OpenClaw authorization bypass in message mutation handling

CVE-2026-62191 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and message processing tool, contains a security flaw in how it handles message modifications. An attacker with low-level access can bypass security checks to perform high-privilege actions they should not be allowed to do. This could lead to unauthorized system changes or service disruptions depending on how the software is configured.

Technical details

An authorization bypass vulnerability exists in OpenClaw's message mutation handling (CWE-862, CWE-863). The flaw allows lower-trust callers to exploit misconfigured input paths to skip requester authorization checks. An attacker with network access and low-level privileges can execute privileged operations if the affected feature is enabled and reachable. The vulnerability impacts integrity and availability but does not appear to expose confidential data. A fix is available in version 2026.6.9.

Affected products

  • OpenClaw OpenClaw >= 2026.6.6, < 2026.6.9

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: NVD publication date

References

Related threats