CVE-2026-62228

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

21 Jul 2026, 19:58

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-8f46-3xx3-8c9m - () https://github.com/openclaw/openclaw/security/advisories/GHSA-8f46-3xx3-8c9m - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-node-exec-approvals - () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-node-exec-approvals - Third Party Advisory
First Time Openclaw
Openclaw openclaw

17 Jul 2026, 02:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-17 02:18

Updated : 2026-07-29 19:16


NVD link : CVE-2026-62228

Mitre link : CVE-2026-62228

CVE.ORG link : CVE-2026-62228


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-863

Incorrect Authorization