Description
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.
Published: 2026-07-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. The flaw allows a caller with lower trust or a configured input path to execute or persist actions outside the intended authorization limits. This bypass can enable non‑allowlisted senders to trigger privileged commands or‑style operations, potentially compromising the confidentiality, integrity or availability of the system.

Affected Systems

The vulnerability affects the OpenClaw application distributed by OpenClaw. It is present in releases 2026.5.14‑beta.1 through 2026.5.26 and is resolved in 2026.5.27 and later. The affected component is the QQBot exec approvals service exposed over the application interface within the Node.js deployment.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. The EPSS score of <1% suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the QQBot exec approvals endpoint when the feature is enabled; the attacker must supply an identity or input path that the system considers lower trust. Because the flaw is an authorization bypass (CWE‑863), success depends on the attacker being able to reach the endpoint and craft a request that exploits the trust boundary. The overall risk for exposed deployments remains high given the impact, but the current probability of exploitation is low.

Generated by OpenCVE AI on July 31, 2026 at 00:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenClaw 2026.5.27 or later to apply the vendor fix.
  • Disable or remove the QQBot exec approvals feature if it is not required.
  • Configure strict allowlisting so that only pre‑approved senders can trigger exec approvals.

Generated by OpenCVE AI on July 31, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.
Title OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-18T03:55:33.359Z

Reserved: 2026-07-13T16:39:44.419Z

Link: CVE-2026-62217

cve-icon Vulnrichment

Updated: 2026-07-17T12:14:07.079Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses