Junglewise Threat Intelligence

CVE-2026-62228: OpenClaw authorization bypass in node exec approvals

CVE-2026-62228 · Severity: high · CVSS 8.8 · Published 2026-07-17

Executive brief

OpenClaw, an automation and execution framework, contains a security flaw in how it handles execution approvals between different environments. An attacker with low-level access could bypass security checks to perform unauthorized actions or gain persistent control over the system. This could lead to a full system compromise, unauthorized data access, or service disruption depending on how the software is configured.

Technical details

An authorization bypass vulnerability (CWE-863) exists in OpenClaw's node exec approvals feature due to mismatched environment configurations between gateways and nodes. Authenticated, lower-trust callers can exploit these environment discrepancies to execute or persist actions that exceed their assigned permissions. The attack requires network access and low-level privileges but no user interaction. The vulnerability is remediated in version 2026.6.5; users are advised to upgrade or restrict the affected feature to trusted operators only.

Affected products

  • OpenClaw OpenClaw < 2026.6.5

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats