Description
OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.
Published: 2026-07-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw Feishu versions before 2026.6.9 contain an incorrect authorization flaw that allows a lower‑trust caller or crafted input to perform actions that normally require stronger policy checks. This privilege escalation, classified as CWE‑863, can lead to unauthorized modification or exposure of Feishu data. The vulnerability arises from the Feishu permission tools ignoring per‑account disablement settings when the feature is enabled and reachable.

Affected Systems

The affected product is OpenClaw Feishu (vendor openclaw:feishu). Deployments running version 2026.6.6 or earlier are vulnerable. The issue was fixed in 2026.6.9; any older deployments should be updated.

Risk and Exploitability

The CVSS score of 8.6 indicates a high‑severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Based on the description, the likely attack vector is an external caller that leverages the enabled Feishu permission tools feature to send crafted inputs or manipulate input paths, bypassing the required policy checks. This flaw is not listed in the CISA KEV catalog, but its high severity and potential for privilege escalation warrant near‑term action.

Generated by OpenCVE AI on August 1, 2026 at 10:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw Feishu to version 2026.6.9 or later to apply the vendor‑supplied fix.
  • If upgrading is not immediately feasible, disable the Feishu permission tools feature to block the bypass pathway.
  • Ensure per‑account disablement settings are enabled and examine access logs for any suspicious activity that may indicate exploitation.

Generated by OpenCVE AI on August 1, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Feishu
Feishu feishu
CPEs cpe:2.3:a:feishu:feishu:*:*:*:*:*:*:*:*
Vendors & Products Feishu
Feishu feishu

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Openclaw
Openclaw feishu
Vendors & Products Openclaw
Openclaw feishu

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.
Title OpenClaw < 2026.6.9 Feishu Authorization Bypass
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:49:54.754Z

Reserved: 2026-07-13T16:36:32.095Z

Link: CVE-2026-62188

cve-icon Vulnrichment

Updated: 2026-07-14T12:58:39.846Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses