CVE-2026-62198
- EPSS 0.2%
- Veröffentlicht 13.07.2026 21:30:18
- Zuletzt bearbeitet 14.07.2026 17:46:31
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to byp...
CVE-2026-62196
- EPSS 0.24%
- Veröffentlicht 13.07.2026 21:30:17
- Zuletzt bearbeitet 15.07.2026 19:18:36
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by lever...
CVE-2026-62194
- EPSS 0.25%
- Veröffentlicht 13.07.2026 21:30:16
- Zuletzt bearbeitet 15.07.2026 05:17:24
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured...
CVE-2026-62195
- EPSS 0.24%
- Veröffentlicht 13.07.2026 21:30:16
- Zuletzt bearbeitet 15.07.2026 05:17:24
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input path...
CVE-2026-62193
- EPSS 0.2%
- Veröffentlicht 13.07.2026 21:30:15
- Zuletzt bearbeitet 15.07.2026 15:16:48
OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input...
CVE-2026-62191
- EPSS 0.22%
- Veröffentlicht 13.07.2026 21:30:14
- Zuletzt bearbeitet 14.07.2026 18:17:36
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured inpu...
CVE-2026-62192
- EPSS 0.25%
- Veröffentlicht 13.07.2026 21:30:14
- Zuletzt bearbeitet 14.07.2026 18:17:30
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input pa...
CVE-2026-62190
- EPSS 0.27%
- Veröffentlicht 13.07.2026 21:30:13
- Zuletzt bearbeitet 15.07.2026 11:16:33
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to b...
CVE-2026-62189
- EPSS 0.25%
- Veröffentlicht 13.07.2026 21:30:12
- Zuletzt bearbeitet 15.07.2026 05:17:24
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy ...
CVE-2026-62186
- EPSS 0.2%
- Veröffentlicht 13.07.2026 21:30:10
- Zuletzt bearbeitet 14.07.2026 18:19:17
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured ...