CVE-2026-62223 – OpenClaw

CVSS 8.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“Small authorization gaps across many features can combine into significant operational risk.”

OpenClaw has released security updates addressing a broad set of High severity vulnerabilities affecting multiple releases prior to 2026.6.9. The update strengthens authorization enforcement, authentication validation, privilege management, environment filtering, network policy controls, and feature-specific security checks across components including plugin installation, browser integration, messaging platforms, device pairing, cron jobs, execution approval workflows, and sandboxed services. These fixes prevent lower-trust users from performing actions beyond their intended permissions and reduce opportunities for unauthorized access and policy bypass.

The affected vulnerabilities include CVSS scores ranging from 7.1 to 8.8, all rated High severity. Several vulnerabilities address authorization bypass and privilege escalation, while others resolve network policy bypass, server-side request forgery, environment filtering weaknesses, race conditions, symlink handling issues, and workspace plugin loading flaws. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Openclaw Openclaw
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-863
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.