Junglewise Threat Intelligence

CVE-2026-62194: OpenClaw privilege escalation in plugin install commands

CVE-2026-62194 · Severity: high · CVSS 8.8 · Published 2026-07-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a platform for managing plugins and gateway operations, contains a security flaw in its plugin installation system. An authorized user with low-level access can bypass security restrictions to perform actions they are not supposed to, potentially taking full control of the system or maintaining permanent access. This could lead to unauthorized data access or disruption of services managed by the platform.

Technical details

A privilege escalation vulnerability exists in OpenClaw's plugin installation commands due to missing authorization checks (CWE-862) and incorrect permission assignment (CWE-732). Authenticated attackers with low-level privileges can exploit misconfigured input paths or specific enabled features to execute arbitrary actions or establish persistence beyond their authorized scope. The vulnerability is reachable over the network and does not require user interaction, though it does require valid low-trust credentials. The issue is resolved in version 2026.6.9; users are advised to upgrade or restrict the plugin installation feature to trusted operators only.

Affected products

  • OpenClaw OpenClaw >= 2026.5.20, < 2026.6.9

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: NVD publication date

References

Related threats