Description
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization bypass in OpenClaw’s native web search. Lower‑trust callers can interact with the search interface, and the software fails to enforce the stronger policy checks that normally guard the operations invoked through that path. As a result, an attacker can perform actions that should be restricted to higher‑privileged users, such as accessing protected resources or executing privileged commands. The weakness corresponds to CWE-863, a flaw in privilege‑based access control.

Affected Systems

OpenClaw OpenClaw versions prior6.6 are affected. The product runs on a Node.js environment; the specific affected releases are those from 2026.5.28 up to and including 2026.6.5.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is <1%, implying a very low exploitation probability in the current environment. Since the vulnerability is not listed in CISA KEV, there is little evidence of active exploitation. The likely attack vector is the web search feature over HTTP/HTTPS, where an attacker crafts requests exploiting misconfigured input paths to bypass authorization logic. The vulnerability requires the ability to use the web search interface; it does not require local privilege elevation or remote code execution, but allows illicit privilege escalation within the application.

Generated by OpenCVE AI on July 31, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.6.6 or later.
  • Restrict access to the native web search endpoint for unconstrained users, or disable the feature entirely for low‑trust callers.
  • Enforce strict role‑based access controls around the actions that can be invoked via the search interface.

Generated by OpenCVE AI on July 31, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.
Title OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T12:54:47.585Z

Reserved: 2026-07-13T16:38:58.353Z

Link: CVE-2026-62198

cve-icon Vulnrichment

Updated: 2026-07-14T12:54:41.816Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses