CVE-2026-62219: Openclaw
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.
Affected products
- Openclaw Openclaw: from 2026.2.12, before 2026.5.26 (fixed in 2026.5.26)
Published 2026-07-17. Last modified 2026-07-21.