Junglewise Threat Intelligence

CVE-2026-62209: OpenClaw authorization bypass in ClickClack agent-mode dispatch

CVE-2026-62209 · Severity: high · CVSS 8.1 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for agent-based task dispatching, contains a security flaw in its ClickClack agent-mode feature. This vulnerability allows users with low-level access to bypass security policies and perform actions they should not be authorized to do. If exploited, an attacker could gain unauthorized access to sensitive data or modify system configurations, potentially compromising the integrity of the entire platform.

Technical details

An authorization bypass vulnerability (CWE-863) exists in OpenClaw's ClickClack agent-mode dispatch feature. The root cause is a failure to correctly enforce the 'toolsAllow' policy check during dispatch operations. A remote attacker with low privileges can exploit this flaw to execute tools or actions that should be restricted by the security policy. This bypass occurs when the affected feature is enabled and reachable via a configured input path. The vulnerability has been addressed in version 2026.6.5.

Affected products

  • OpenClaw OpenClaw >= 2026.5.10-beta.1, < 2026.6.5

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats