Junglewise Threat Intelligence

CVE-2026-62221: OpenClaw incorrect authorization in ClickClack allowFrom feature

CVE-2026-62221 · Severity: medium · CVSS 5.4 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an automation tool that manages command execution through its ClickClack feature. A security flaw in the 'allowFrom' configuration allows users with low-level access to bypass security restrictions and run unauthorized commands. This could lead to unauthorized data access or unintended changes to the system's configuration.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the ClickClack 'allowFrom' feature of OpenClaw. When this feature is enabled, the application fails to properly validate the authorization of callers or input paths, allowing lower-trust actors to execute or persist actions beyond their intended scope. This includes the ability to run commands that are not explicitly included in the configured allowlist. The attack is reachable over the network and requires low-level authenticated privileges. The issue is resolved in version 2026.5.26.

Affected products

  • OpenClaw OpenClaw >= 2026.5.12, < 2026.5.26

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date
  • 2026-05-26: patched: First stable patched version released

References

Related threats