Junglewise Threat Intelligence

CVE-2026-62219: OpenClaw authorization bypass in hooks allowedAgentIds validation

CVE-2026-62219 · Severity: high · CVSS 7.1 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing automated agents and gateway operations, contains a security flaw in how it validates user permissions. An attacker with low-level access can bypass security restrictions by providing empty identification values, allowing them to perform unauthorized actions that should be restricted to high-trust users. This could lead to unauthorized data modification or the execution of restricted administrative tasks.

Technical details

An authorization bypass vulnerability exists in OpenClaw versions 2026.2.12 through 2026.5.25 due to improper validation in the 'hooks allowedAgentIds' component. The vulnerability (CWE-863) allows a lower-trust caller or a configured input path to bypass agent ID restrictions by submitting blank agent IDs. This occurs because the validation logic fails to correctly handle empty inputs, effectively treating them as authorized. An authenticated attacker with network access and low privileges can exploit this to perform actions that should require stronger authorization or specific policy checks. The issue is resolved in version 2026.5.26.

Affected products

  • OpenClaw OpenClaw 2026.2.12 to 2026.5.25

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date

References

Related threats