CVE-2026-62229
- EPSS 0.45%
- Veröffentlicht 17.07.2026 00:07:06
- Zuletzt bearbeitet 30.07.2026 14:49:36
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob...
CVE-2026-62227
- EPSS 0.23%
- Veröffentlicht 17.07.2026 00:07:05
- Zuletzt bearbeitet 21.07.2026 20:00:20
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach networ...
CVE-2026-62228
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:07:05
- Zuletzt bearbeitet 29.07.2026 19:16:50
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can explo...
CVE-2026-62226
- EPSS 0.24%
- Veröffentlicht 17.07.2026 00:07:04
- Zuletzt bearbeitet 21.07.2026 19:57:34
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiri...
CVE-2026-62225
- EPSS 0.15%
- Veröffentlicht 17.07.2026 00:07:03
- Zuletzt bearbeitet 21.07.2026 02:16:23
OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restriction...
CVE-2026-62223
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:07:02
- Zuletzt bearbeitet 20.07.2026 16:57:40
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to exe...
CVE-2026-62222
- EPSS 0.12%
- Veröffentlicht 17.07.2026 00:07:01
- Zuletzt bearbeitet 29.07.2026 19:16:50
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their ...
CVE-2026-62220
- EPSS 0.29%
- Veröffentlicht 17.07.2026 00:07:00
- Zuletzt bearbeitet 21.07.2026 20:01:26
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume ...
CVE-2026-62221
- EPSS 0.14%
- Veröffentlicht 17.07.2026 00:07:00
- Zuletzt bearbeitet 21.07.2026 20:00:31
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actio...
CVE-2026-62219
- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:06:59
- Zuletzt bearbeitet 21.07.2026 19:58:07
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions ...