CVE-2026-62198: Openclaw
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.
Affected products
- Openclaw Openclaw: from 2026.5.28, before 2026.6.6 (fixed in 2026.6.6)
Published 2026-07-13. Last modified 2026-07-14.