Junglewise Threat Intelligence

CVE-2026-62202: OpenClaw privilege escalation in isolated cron jobs

CVE-2026-62202 · Severity: high · CVSS 8.8 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing automated tasks and gateways, contains a security flaw in its scheduled task (cron) feature. This vulnerability allows users with low-level access to bypass security restrictions and gain unauthorized control over execution tools they should not be able to use. An attacker could exploit this to perform actions beyond their intended permissions, potentially leading to full system compromise or persistent unauthorized access.

Technical details

A privilege escalation vulnerability exists in OpenClaw's isolated cron job feature due to incorrect authorization (CWE-863). The flaw allows an authenticated attacker with low privileges to leverage misconfigured input paths to regain access to execution tools that were explicitly denied by policy. By exploiting this, a caller can execute or persist actions beyond their intended authorization boundaries. The vulnerability is reachable over the network if the affected feature is enabled. A fix is available in version 2026.6.9, and users are advised to restrict the feature to trusted operators or disable it as a mitigation.

Affected products

  • OpenClaw OpenClaw 2026.6.1 to 2026.6.8

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD and VulnCheck publication date
  • 2026-06-30: patched: Version 2026.6.9 released

References

Related threats