CVE-2026-62225
- EPSS 0.15%
- Veröffentlicht 17.07.2026 00:07:03
- Zuletzt bearbeitet 21.07.2026 02:16:23
OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restriction...
CVE-2026-62223
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:07:02
- Zuletzt bearbeitet 20.07.2026 16:57:40
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to exe...
CVE-2026-62222
- EPSS 0.12%
- Veröffentlicht 17.07.2026 00:07:01
- Zuletzt bearbeitet 29.07.2026 19:16:50
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their ...
CVE-2026-62220
- EPSS 0.29%
- Veröffentlicht 17.07.2026 00:07:00
- Zuletzt bearbeitet 21.07.2026 20:01:26
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume ...
CVE-2026-62221
- EPSS 0.14%
- Veröffentlicht 17.07.2026 00:07:00
- Zuletzt bearbeitet 21.07.2026 20:00:31
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actio...
CVE-2026-62219
- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:06:59
- Zuletzt bearbeitet 21.07.2026 19:58:07
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions ...
CVE-2026-62217
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:06:58
- Zuletzt bearbeitet 21.07.2026 19:59:25
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller'...
CVE-2026-62218
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:06:58
- Zuletzt bearbeitet 21.07.2026 19:58:34
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by r...
- EPSS 0.21%
- Veröffentlicht 17.07.2026 00:06:57
- Zuletzt bearbeitet 23.07.2026 20:17:19
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (...
CVE-2026-62214
- EPSS 0.31%
- Veröffentlicht 17.07.2026 00:06:56
- Zuletzt bearbeitet 08.10.2026 16:17:26
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply mali...