Description
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.
Published: 2026-07-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions prior to 2026.6.5 contain an authorization bypass in the ClickClack agent‑mode dispatch feature. The bug allows the tool to ignore the toolsAllow policy check, so callers with lower trust or attacks that supply a configured input path can invoke actions that normally require stronger authorization. The resulting compromise could allow an attacker to read, modify, or delete data and potentially disrupt application functionality.

Affected Systems

The affected product is OpenClaw OpenClaw released as software for Node.js environments. Vulnerable releases include 2026.5.10-beta.1 and all earlier versions up to but not including 2026.6.5. Users running these versions should verify their deployment environment and confirm whether the ClickClack agent‑mode dispatch feature is enabled.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity, while the EPSS score of less than 1 percent shows that currently the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation. If the affected feature is reachable—either through a publicly exposed API or a local service—an attacker who can manipulate input paths or impersonate a lower‑trust caller can trigger the bypass. The attack vector is inferred to be local or remote access to the dispatch endpoint, and requires the feature to be enabled and reachable.

Generated by OpenCVE AI on July 31, 2026 at 00:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.6.5 or later
  • If upgrading is not immediately possible, disable the ClickClack agent‑mode dispatch feature
  • Validate all input paths and enforce the toolsAllow policy during dispatch

Generated by OpenCVE AI on July 31, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.
Title OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-18T03:55:32.532Z

Reserved: 2026-07-13T16:39:22.251Z

Link: CVE-2026-62209

cve-icon Vulnrichment

Updated: 2026-07-17T13:33:26.890Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses