Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2959 articles · 183563 vulns · 37/41 feeds (7d)
← Back to list
9.0
CVE-2026-62229EXPLOITEDPATCHED
openclaw · openclaw

OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching

Description

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the affected feature is enabled.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-34mr-7r3m-gfg7(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-glob-matching(third-party-advisory)

Related News (1 articles)

Tier C
VulDB18d ago
CVE-2026-62229 | OpenClaw up to 2026.5.17 Glob Matching authorization
→ No new info (linked only)
CVSS 3.19.0 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2026.5.18
CWECWE-22
PublishedJul 17, 2026
Last enriched18d agov2
Tags
privilege escalationcode executiondata disclosuresecurity bypass
Trending Score3
Source articles1
Independent1
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-62220
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
Trending: 4
CRITICALCVE-2026-62198
OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
Trending: 3
NONECVE-2026-62207
OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
Trending: 3
NONECVE-2026-62223
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
Trending: 3
NONECVE-2026-62203
OpenClaw < 2026.6.6 Environment Variable Injection via rustup
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, cvssEstimate, affectedVersions
Jul 17, 2026
Actively Exploited
Jul 18, 2026
Exploit Available
Jul 18, 2026
Patch Available
Jul 18, 2026

Version History

v2
Last enriched 18d ago
v2Tier C18d ago

Updated severity to CRITICAL, set CVSS estimate to 9.0, corrected exploitAvailable to false, and refined affected versions to '< 2026.5.17'

severitycvssEstimateaffectedVersions
via VulDB
v118d ago

Initial creation