CVE-2026-62216: Openclaw

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.

Affected products

  • Openclaw Openclaw: from 2026.4.20, before 2026.5.28 (fixed in 2026.5.28)

Published 2026-07-17. Last modified 2026-07-23.