Junglewise Threat Intelligence

CVE-2026-62223: OpenClaw authorization bypass in device-pair approval

CVE-2026-62223 · Severity: high · CVSS 8.8 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing device connections and gateway operations, contains a security flaw in its device-pairing approval system. An attacker with low-level access can bypass authorization checks to perform actions they should not be allowed to do, such as running unauthorized commands. This could lead to a full system takeover, data theft, or service disruption if the device-pairing feature is enabled.

Technical details

An authorization bypass vulnerability (CWE-863) exists in OpenClaw's device-pair approval feature due to improper privilege management and incorrect neutralization of input paths. Authenticated attackers with low privileges can exploit misconfigured input paths to execute or persist unauthorized actions, potentially leading to OS command injection (CWE-78) via the 'system.run' node. The attack is reachable over the network if the device-pairing feature is enabled. The vulnerability is addressed in version 2026.5.18; users are advised to upgrade or restrict the feature to trusted operators.

Affected products

  • OpenClaw OpenClaw < 2026.5.18

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date

References

Related threats