Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2959 articles · 183559 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-62207PATCHED
openclaw · openclaw

OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools

Description

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-cf2p-f286-mphf(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-admin-tools(third-party-advisory)

Related News (1 articles)

Tier C
VulDB18d ago
CVE-2026-62207 | OpenClaw up to 2026.6.4 improper authorization
→ No new info (linked only)
CVSS 3.18.8 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.6.5
CWECWE-862
PublishedJul 17, 2026
Last enriched18d agov2
Trending Score3
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-62220
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
Trending: 4
CRITICALCVE-2026-62198
OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
Trending: 3
NONECVE-2026-62229EXP
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
Trending: 3
NONECVE-2026-62223
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
Trending: 3
NONECVE-2026-62203
OpenClaw < 2026.6.6 Environment Variable Injection via rustup
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, affectedVersions
Jul 17, 2026
Patch Available
Jul 29, 2026

Version History

v2
Last enriched 18d ago
v2Tier C18d ago

Updated severity from NONE to CRITICAL and clarified affected versions as all versions up to 2026.6.4

severityaffectedVersions
via VulDB
v118d ago

Initial creation