CVE-2026-62192 – OpenClaw
“Small authorization gaps across many features can combine into significant operational risk.”
OpenClaw has released security updates addressing a broad set of High severity vulnerabilities affecting multiple releases prior to 2026.6.9. The update strengthens authorization enforcement, authentication validation, privilege management, environment filtering, network policy controls, and feature-specific security checks across components including plugin installation, browser integration, messaging platforms, device pairing, cron jobs, execution approval workflows, and sandboxed services. These fixes prevent lower-trust users from performing actions beyond their intended permissions and reduce opportunities for unauthorized access and policy bypass.
The affected vulnerabilities include CVSS scores ranging from 7.1 to 8.8, all rated High severity. Several vulnerabilities address authorization bypass and privilege escalation, while others resolve network policy bypass, server-side request forgery, environment filtering weaknesses, race conditions, symlink handling issues, and workspace plugin loading flaws. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.
Key Details
- Affected Product
- Openclaw Openclaw
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-863