Description
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.6.9 contain an authorization bypass in the message mutation handling path that allows callers with lower trust levels to perform actions that normally require higher privileges. The flaw arises from missing or inadequate authorization checks during mutation processing, as identified by CWE-862 and CWE-863. Attackers can trigger privileged operations by sending crafted mutation requests, potentially compromising data confidentiality, integrity, and availability of the application.

Affected Systems

The affected product is OpenClaw, specifically any Node.js deployment running OpenClaw 2026.6.6 through 2026.6.8. Users who have not upgraded to version 2026.6.9 or later are exposed to this vulnerability.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS value of less than 1% suggests a low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves accessing the message mutation feature via misconfigured input paths, allowing an attacker to inject authorization‑bypassing requests when the feature is enabled and reachable.

Generated by OpenCVE AI on July 31, 2026 at 11:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.6.9 or later, which eliminates the authorization bypass issue.
  • Disable the message mutation feature or restrict its access when it is not required for business processes.
  • Enforce proper authorization checks and validate input on all mutation endpoints to prevent bypass attempts.

Generated by OpenCVE AI on July 31, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title OpenClaw 2026.6.6 < 2026.6.8 Authorization Bypass via Message Mutations OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.
Title OpenClaw 2026.6.6 < 2026.6.8 Authorization Bypass via Message Mutations
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T12:52:39.220Z

Reserved: 2026-07-13T16:36:32.095Z

Link: CVE-2026-62191

cve-icon Vulnrichment

Updated: 2026-07-14T12:52:35.738Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses