Junglewise Threat Intelligence

CVE-2026-62207: OpenClaw authentication bypass in admin-scoped tools

CVE-2026-62207 · Severity: high · CVSS 8.8 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing gateway operations and plugins, contains a security flaw that allows users with low-level access to perform administrative actions. By exploiting this vulnerability, an attacker who already has basic access to the system can bypass security restrictions to access sensitive administrative tools. This could lead to unauthorized data access, system modifications, or a complete takeover of the affected service.

Technical details

An authentication bypass vulnerability exists in OpenClaw versions prior to 2026.6.5 due to missing or incorrect authorization checks (CWE-862/CWE-863). The flaw resides in how the application validates input paths for admin-scoped tools, allowing identity-bearing HTTP callers with low privileges to execute functions intended for administrators. An attacker with network access and valid low-level credentials can exploit this by providing specific input paths that bypass policy checks. This can result in full compromise of confidentiality, integrity, and availability. The issue is resolved in version 2026.6.5; users are advised to upgrade or restrict access to administrative features to trusted operators only.

Affected products

  • OpenClaw OpenClaw < 2026.6.5

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD and VulnCheck publication date
  • 2026-06-30: patched: Version 2026.6.5 released

References

Related threats