Junglewise Threat Intelligence

CVE-2026-62206: OpenClaw missing authorization in Discord moderation actions

CVE-2026-62206 · Severity: high · CVSS 7.1 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing Discord integrations and moderation, contains a flaw where certain moderation commands do not properly verify user permissions. This allows users with low-level access to perform administrative actions, such as banning or kicking users, that should be restricted to trusted moderators. The impact depends on how the bot is configured, but it could lead to unauthorized management of a Discord community.

Technical details

A missing authorization vulnerability (CWE-862) exists in OpenClaw's Discord moderation action handlers. In affected versions, the software fails to perform adequate trusted requester checks or policy validation on specific input paths. This allows an authenticated attacker with low privileges (PR:L) to trigger moderation actions over the network without the required higher-level authorization. The vulnerability is addressed in version 2026.6.9; users are advised to upgrade or restrict moderation features to trusted operators only.

Affected products

  • OpenClaw OpenClaw < 2026.6.9

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date

References

Related threats