Description
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.
Published: 2026-07-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions 2026.3.22 through, but not including, 2026.6.6 contain an authorization bypass that lets a lower‑trust user satisfy an elevated sender allowlist by leveraging WhatsApp group IDs. The flaw enables attackers to perform actions normally reserved for higher‑level permissions, thereby compromising the integrity of privileged operations. The vulnerability is classified as CWE‑863 (Authorization Bypass Through User‑Controlled Key).

Affected Systems

The OpenClaw application is affected, specifically versions released 2026.3.22 and any earlier than 2026.6.6. All deployments running these versions are susceptible to the bypass unless the feature is disabled or reconfigured.

Risk and Exploitability

The CVSS score of 8.7 places the issue in the high severity range. The EPSS score of less than 1% indicates a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to interact with the application’s message handling interface to submit a WhatsApp group ID that is present in the elevated sender allowlist. The vector is inferred to be remote, as the attacker must submit a message to the application’s interface, but this is not explicitly stated in the advisory. The combination of a high severity rating and the privilege escalation potential therefore poses a significant risk for affected deployments.

Generated by OpenCVE AI on August 1, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy any security update for OpenClaw that addresses the authorization bypass in versions prior to 2026.6.6, as indicated by vendor advisory releases.
  • If an update is not yet available, temporarily disable or remove the WhatsApp group ID validation logic in the affected feature to prevent the bypass from being exercised.
  • Review and tighten the sender allowlist configuration to ensure that only approved, trusted group IDs are retained, and enforce the minimum trust level required for privileged operations.

Generated by OpenCVE AI on August 1, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.
Title OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-15T19:07:59.623Z

Reserved: 2026-07-13T16:38:58.353Z

Link: CVE-2026-62196

cve-icon Vulnrichment

Updated: 2026-07-15T19:07:56.426Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses