- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:06:56
- Zuletzt bearbeitet 20.07.2026 16:58:30
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting craf...
CVE-2026-62213
- EPSS 0.26%
- Veröffentlicht 17.07.2026 00:06:55
- Zuletzt bearbeitet 08.10.2026 16:17:26
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should rem...
- EPSS 0.11%
- Veröffentlicht 17.07.2026 00:06:54
- Zuletzt bearbeitet 29.07.2026 21:17:47
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured in...
CVE-2026-62212
- EPSS 0.17%
- Veröffentlicht 17.07.2026 00:06:54
- Zuletzt bearbeitet 20.07.2026 16:59:11
OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation ...
CVE-2026-62210
- EPSS 0.31%
- Veröffentlicht 17.07.2026 00:06:53
- Zuletzt bearbeitet 23.07.2026 20:17:19
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that...
CVE-2026-62208
- EPSS 0.26%
- Veröffentlicht 17.07.2026 00:06:52
- Zuletzt bearbeitet 20.07.2026 17:00:44
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended aut...
CVE-2026-62209
- EPSS 0.21%
- Veröffentlicht 17.07.2026 00:06:52
- Zuletzt bearbeitet 21.07.2026 19:59:43
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller...
CVE-2026-62207
- EPSS 0.3%
- Veröffentlicht 17.07.2026 00:06:51
- Zuletzt bearbeitet 29.07.2026 19:16:50
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on c...
CVE-2026-62205
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:06:50
- Zuletzt bearbeitet 21.07.2026 20:00:45
OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform ...
CVE-2026-62206
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:06:50
- Zuletzt bearbeitet 20.07.2026 17:00:58
OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger a...