Description
OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Published: 2026-07-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions prior to 2026.6.9 suffer from a missing authorization check in Discord moderation actions. The flaw allows a caller with lower trust or an externally supplied input path to execute moderation commands that would normally require higher privileges or a stricter policy check. The resulting impact is an unauthorized ability to perform moderation actions such as bans, mutes, or message deletions, potentially harming users or disrupting server operations. The severity of the practical results relies on how a lower‑trust input can reach the vulnerable pathway, but the flaw clearly enables escalation of privileges within the bot's control domain.

Affected Systems

The vulnerability applies to the OpenClaw project, specifically the OpenClaw software. All releases dated earlier than version 2026.6.9 are affected. Users operating those earlier releases are at risk if their configuration allows lower‑trust callers or if untrusted input can be supplied to the moderation functionality.

Risk and Exploitability

The CVSS score of 6 indicates moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector would involve crafting a request to a Discord moderation endpoint that OpenClaw processes, using an unprivileged or compromised input to trigger the action. Successful exploitation requires that the attacker can supply such a request or that lower‑trust input paths are not adequately filtered, allowing the bot to act on commands without the required authorization.

Generated by OpenCVE AI on July 31, 2026 at 00:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OpenClaw release 2026.6.9 or later to eliminate the missing authorization check.
  • Reconfigure the bot or its deployment environment to ensure only trusted users or roles can invoke moderation actions, closing any lower‑trust input pathways that might reach the affected code.
  • Enable auditing and logging of all moderation commands, and monitor for anomalous activity that could indicate unauthorized use of the bot’s moderation capabilities.

Generated by OpenCVE AI on July 31, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Title OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-862
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-17T14:17:25.499Z

Reserved: 2026-07-13T16:39:22.251Z

Link: CVE-2026-62206

cve-icon Vulnrichment

Updated: 2026-07-17T14:17:20.653Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses