Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2959 articles · 183563 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-62198PATCHED
openclaw · openclaw

OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search

Description

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.

Affected Products

VendorProductVersions
openclawopenclaw2026.5.28

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-v4f6-x5g5-2g4g(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-web-search(third-party-advisory)

Related News (1 articles)

Tier C
VulDB21d ago
CVE-2026-62198 | OpenClaw up to 2026.6.5 Web Search authorization
→ No new info (linked only)
CVSS 3.14.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.6.6
CWECWE-863
PublishedJul 13, 2026
Last enriched21d agov2
Trending Score3
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-62220
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
Trending: 4
NONECVE-2026-62229EXP
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
Trending: 3
NONECVE-2026-62207
OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
Trending: 3
NONECVE-2026-62223
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
Trending: 3
NONECVE-2026-62203
OpenClaw < 2026.6.6 Environment Variable Injection via rustup
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 13, 2026
Patch Available
Jul 13, 2026
Discovered by ZDM
Jul 13, 2026
Updated: severity
Jul 13, 2026

Version History

v2
Last enriched 21d ago
v2Tier C21d ago

Updated severity to CRITICAL and corrected exploit availability to false.

severity
via VulDB
v121d ago

Initial creation