Description
OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.
Published: 2026-07-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A lower‑trust caller or a specially configured input path in OpenClaw Feishu tools (npm package @openclaw/feishu) can bypass per‑account disablement checks, allowing an attacker to perform privileged actions that should have required stronger authorization. The flaw enables unauthorized operations and therefore poses a risk of data exposure or manipulation. This vulnerability is characterized as a CWE‑863 fault, reflecting a failure to verify access rights before executing configuration changes or resource operations.

Affected Systems

The affected component is the OpenClaw Feishu tools package for Feishu. Versions up to and including 2026.6.6 are vulnerable. The issue was fixed in version 2026.6.9; any deployment using that or newer releases is considered safe. Systems that rely on @openclaw/feishu and have not upgraded past 2026.6.6 are at risk.

Risk and Exploitability

The CVSS score of 8.6 places this flaw in the high‑severity range, indicating that an adversary could achieve significant impact if exploited. The EPSS score is less than 1 %, which suggests that the likelihood of exploitation is low, though not zero. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely to be remote or local depending on how the Feishu tool is exposed; a lower‑trust caller or malicious input path that the tool accepts can trigger the bypass.

Generated by OpenCVE AI on July 31, 2026 at 11:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the @openclaw/feishu npm package to version 2026.6.9 or later
  • If an upgrade cannot be performed immediately, restrict the Feishu tool to trusted callers by tightening configuration and enforcing explicit policy checks around privileged actions
  • Validate all input paths and authenticate caller trust levels before execution of sensitive operations, following OAuth or other role‑based access controls recommended for the environment
  • Consider configuring network firewall rules to isolate the Feishu tool endpoint from untrusted networks

Generated by OpenCVE AI on July 31, 2026 at 11:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Feishu
Feishu feishu
CPEs cpe:2.3:a:feishu:feishu:*:*:*:*:*:*:*:*
Vendors & Products Feishu
Feishu feishu

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Openclaw
Openclaw feishu
Vendors & Products Openclaw
Openclaw feishu

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.
Title OpenClaw < 2026.6.9 Feishu tools Authorization Bypass
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:49:53.885Z

Reserved: 2026-07-13T16:36:32.095Z

Link: CVE-2026-62187

cve-icon Vulnrichment

Updated: 2026-07-15T10:32:57.761Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:30:05Z

Weaknesses