Junglewise Threat Intelligence

CVE-2026-62198: OpenClaw authorization bypass in native web search

CVE-2026-62198 · Severity: medium · CVSS 4.3 · Published 2026-07-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for web search integration, contains a security flaw in its native web search feature. This vulnerability allows users with low-level access to bypass security policies and perform actions that should be restricted to highly trusted administrators. If exploited, an attacker could access sensitive information or execute operations they are not authorized to perform, potentially compromising the integrity of the search gateway.

Technical details

An authorization bypass vulnerability (CWE-863/CWE-284) exists in OpenClaw's native web search component. The flaw stems from incorrect authorization checks where the system fails to properly enforce tool policies when processing specific input paths. A remote attacker with low-level privileges can exploit this to bypass intended security boundaries and execute restricted operations or access data that should require higher trust levels. The vulnerability is reachable over the network if the native web search feature is enabled. A fix is available in version 2026.6.6, and users are advised to restrict the feature to trusted operators or disable it until patched.

Affected products

  • OpenClaw OpenClaw >= 2026.5.28, < 2026.6.6

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: NVD publication date
  • 2026-06-30: patched: Version 2026.6.6 released

References

Related threats