CVE-2026-62217
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:06:58
- Zuletzt bearbeitet 21.07.2026 19:59:25
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller'...
CVE-2026-62218
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:06:58
- Zuletzt bearbeitet 21.07.2026 19:58:34
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by r...
- EPSS 0.21%
- Veröffentlicht 17.07.2026 00:06:57
- Zuletzt bearbeitet 23.07.2026 20:17:19
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (...
CVE-2026-62214
- EPSS 0.31%
- Veröffentlicht 17.07.2026 00:06:56
- Zuletzt bearbeitet 20.07.2026 16:58:47
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply mali...
- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:06:56
- Zuletzt bearbeitet 20.07.2026 16:58:30
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting craf...
CVE-2026-62213
- EPSS 0.26%
- Veröffentlicht 17.07.2026 00:06:55
- Zuletzt bearbeitet 21.07.2026 00:17:48
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should rem...
- EPSS 0.11%
- Veröffentlicht 17.07.2026 00:06:54
- Zuletzt bearbeitet 29.07.2026 21:17:47
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured in...
CVE-2026-62212
- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:06:54
- Zuletzt bearbeitet 20.07.2026 16:59:11
OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation ...
CVE-2026-62210
- EPSS 0.31%
- Veröffentlicht 17.07.2026 00:06:53
- Zuletzt bearbeitet 23.07.2026 20:17:19
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that...
CVE-2026-62208
- EPSS 0.26%
- Veröffentlicht 17.07.2026 00:06:52
- Zuletzt bearbeitet 20.07.2026 17:00:44
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended aut...