CVE-2026-62219: Openclaw

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.

Affected products

  • Openclaw Openclaw: from 2026.2.12, before 2026.5.26 (fixed in 2026.5.26)

Published 2026-07-17. Last modified 2026-07-21.