Description
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
Published: 2026-07-17
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions 2026.5.12 through 2026.5.25 contain an authorization flaw in the ClickClack allowFrom feature. The flaw allows a caller with lower trust or a specifically configured input path to perform actions beyond the caller’s intended authorization, including executing commands that are not on the allowlist. This results in an unchecked privilege escalation within the application, as the feature does not enforce the proper authentication checks before processing the request, exposing the system to unintended code execution.

Affected Systems

The affected product is OpenClaw, a Node.js‑based tool, with vulnerable releases ranging from 2026.5.12 up to, but not including, 2026.5.26. Any deployment that uses these versions and has the ClickClack allowFrom feature enabled is susceptible to exploitation. Administrators should verify the exact version and whether the feature is active.

Risk and Exploitability

The CVSS score of 2.3 indicates a low severity rating, and the EPSS score of less than 1% points to a very small likelihood of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an externally reachable endpoint that has the allowFrom feature enabled; an attacker would need to craft a request that targets this feature to trigger the Bypass. Because the flaw permits command execution outside the allowlist, a successful exploitation could affect the integrity and availability of the affected system, but only for users whose requests reach the vulnerable endpoint.

Generated by OpenCVE AI on July 31, 2026 at 00:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to 2026.5.26 or later to eliminate the flaw.
  • Disable the ClickClack allowFrom feature if it is not required for business operations.
  • Configure allowFrom paths to accept input only from trusted networks and restrict command execution to the allowlist.

Generated by OpenCVE AI on July 31, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.
Title OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-17T18:05:57.721Z

Reserved: 2026-07-13T16:39:44.420Z

Link: CVE-2026-62221

cve-icon Vulnrichment

Updated: 2026-07-17T12:53:31.672Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses