CVE-2026-62211: Openclaw

Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

Affected products

  • Openclaw Openclaw: before 2026.6.1 (fixed in 2026.6.1)

Published 2026-07-17. Last modified 2026-07-29.