CVE-2026-62226: Openclaw
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.
Affected products
- Openclaw Openclaw: from 2026.3.28, before 2026.5.19 (fixed in 2026.5.19)
Published 2026-07-17. Last modified 2026-07-21.