Junglewise Threat Intelligence

CVE-2026-62215: OpenClaw authentication bypass in HTTP Canvas responses

CVE-2026-62215 · Severity: high · CVSS 8 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing gateway operations and user interfaces, contains a security flaw in how it handles certain web-based responses. An attacker could trick the system into performing unauthorized actions by forging trusted commands, potentially leading to a full takeover of the application's interface or sensitive data. This risk is highest when the software is configured to accept inputs from untrusted sources.

Technical details

An authentication bypass vulnerability exists in OpenClaw's HTTP Canvas response handling due to insufficient verification of data authenticity (CWE-345). The flaw allows a lower-trust caller or a crafted input path to forge trusted A2UI actions, effectively bypassing intended authorization policies. Exploitation requires a network-based attacker to submit crafted requests through configured input paths, though it typically requires high attack complexity and user interaction (UI:R). If successful, an attacker can perform actions that should require stronger authorization, potentially leading to a compromise of confidentiality and integrity. The issue is addressed in version 2026.6.5.

Affected products

  • OpenClaw OpenClaw < 2026.6.5

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats